CIS Ubuntu Linux 24.04 LTS Benchmark · Section 3

Ubuntu 24.04 Network: 1 Check

Wartiva runs 1 check for section 3, Network, of the CIS Ubuntu Linux 24.04 LTS Benchmark. It lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

1 check on this page

3.1 Configure Network Devices

Ensure Bluetooth services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 3.1

Finding: Bluetooth service is in use.

Checks whether the Bluetooth (bluez) service is masked or stopped on the endpoint.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: Bluetooth is a short-range wireless path an attacker can use for bluesnarfing or to spread malicious code; disabling it on systems with no operational need reduces the attack surface.

Impact: Bluetooth peripherals such as wireless keyboards and mice will no longer be able to connect to the system.

Remediation

From the command line:

systemctl stop bluetooth.service
systemctl mask bluetooth.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)