CIS Ubuntu Linux 24.04 LTS Benchmark · Section 2

Ubuntu 24.04 Services: 31 Checks

Wartiva runs 31 checks for section 2, Services, of the CIS Ubuntu Linux 24.04 LTS Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 31 checks on this page

2.1 Configure Server Services

Ensure autofs services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Autofs service is in use.

Checks that the autofs automounting service is masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: Automounting lets anyone with physical access attach removable media and have its contents mounted without explicit permission, widening the attack surface.

Impact: Automatic mounting of configured removable media stops; media must be mounted manually.

Remediation

From the command line:

systemctl stop autofs.service
systemctl mask autofs.service
Framework mappings
  • CIS Controls v8: 10.3 Disable Autorun and Autoplay for Removable Media
  • NIST SP 800-53 Rev. 5: MP-7 Media Use
  • NIST SP 800-171 Rev. 2: 3.8.7 Control the use of removable media on system components
  • CMMC 2.0 Level 2: MP.L2-3.8.7 Control the use of removable media on system components
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure avahi daemon services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Avahi daemon service is in use.

Checks that the avahi-daemon service and socket are masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: Avahi zeroconf service discovery is rarely needed and publishes/advertises services on the local network, expanding attack surface.

Impact: Automatic discovery of local network services and printers via mDNS/DNS-SD stops.

Remediation

From the command line:

systemctl stop avahi-daemon.socket avahi-daemon.service
systemctl mask avahi-daemon.socket avahi-daemon.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure dhcp server services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Dhcp server service is in use.

Checks that the kea DHCPv4/DHCPv6/DDNS server services are masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: A rogue or misconfigured DHCP server can disrupt the network by handing out incorrect addresses, DNS servers, or gateways; unless the host is a DHCP server the kea services should not run.

Impact: The system can no longer serve DHCP leases.

Remediation

From the command line:

systemctl stop kea-dhcp-ddns-server.service kea-dhcp4-server.service kea-dhcp6-server.service
systemctl mask kea-dhcp-ddns-server.service kea-dhcp4-server.service kea-dhcp6-server.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure dns server services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Dns server service is in use.

Checks that the bind9 DNS server (named.service) is masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: Unless the host is a designated DNS server, the bind9 package/service should not run so as to reduce attack surface.

Impact: The system can no longer serve DNS.

Remediation

From the command line:

systemctl stop named.service
systemctl mask named.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure dnsmasq services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Dnsmasq service is in use.

Checks that the dnsmasq service is masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: dnsmasq provides DNS caching/forwarding and DHCP; unless required it should not run.

Impact: Local DNS caching/forwarding and DHCP via dnsmasq stop.

Remediation

From the command line:

systemctl stop dnsmasq.service
systemctl mask dnsmasq.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure ftp server services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Ftp server service is in use.

Checks that the vsftpd FTP server service is masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: FTP transmits data and credentials in the clear; unless an FTP server is required, vsftpd should not run.

Impact: The system can no longer act as an FTP server.

Remediation

From the command line:

systemctl stop vsftpd.service
systemctl mask vsftpd.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure ldap server services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Ldap server service is in use.

Checks that the slapd OpenLDAP server service is masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: Unless the host is an LDAP server, slapd should not run so as to reduce attack surface.

Impact: The system can no longer serve LDAP directory queries.

Remediation

From the command line:

systemctl stop slapd.service
systemctl mask slapd.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure message access server services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Message access server service is in use.

Checks that the dovecot IMAP/POP3 server service and socket are masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: Unless the host provides IMAP/POP3 mail access, the dovecot service should not run so as to reduce attack surface.

Impact: IMAP/POP3 message access served by dovecot stops.

Remediation

From the command line:

systemctl stop dovecot.socket dovecot.service
systemctl mask dovecot.socket dovecot.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure network file system services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Network file system service is in use.

Checks that the NFS server service (nfs-server.service) is masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: If the host does not export NFS shares, the nfs-kernel-server service should not run so as to reduce the remote attack surface.

Impact: The system can no longer export NFS shares.

Remediation

From the command line:

systemctl stop nfs-server.service
systemctl mask nfs-server.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure nis server services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Nis server service is in use.

Checks that the ypserv NIS server service is masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: NIS is inherently insecure (weak authentication, DoS and buffer-overflow history) and has been superseded by LDAP; ypserv should not run.

Impact: The system can no longer serve NIS maps.

Remediation

From the command line:

systemctl stop ypserv.service
systemctl mask ypserv.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure rpcbind services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Rpcbind service is in use.

Checks that the rpcbind (portmapper) service and socket are masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: The portmapper is a UDP amplification vector suited to DDoS attacks; unless RPC services are required, rpcbind should not run.

Impact: RPC-based services (e.g. NFS) that depend on rpcbind will not function.

Remediation

From the command line:

systemctl stop rpcbind.socket rpcbind.service
systemctl mask rpcbind.socket rpcbind.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure rsync services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Rsync service is in use.

Checks that the rsync daemon service is masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: The rsync protocol is unencrypted; the rsync daemon should not run so as to reduce attack surface.

Impact: Serving files via the rsync daemon stops (rsync-over-ssh is unaffected).

Remediation

From the command line:

systemctl stop rsync.service
systemctl mask rsync.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure samba file server services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Samba file server service is in use.

Checks that the Samba file server service (smbd.service) is masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: Unless SMB file/directory sharing to Windows clients is needed, smbd should not run so as to reduce attack surface.

Impact: SMB file/print sharing stops.

Remediation

From the command line:

systemctl stop smbd.service
systemctl mask smbd.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure snmp services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Snmp service is in use.

Checks that the SNMP server service (snmpd.service) is masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: SNMPv1/v2 transmit community strings and data in the clear; unless SNMP is required (and hardened to v3), snmpd should not run.

Impact: SNMP monitoring of the host stops.

Remediation

From the command line:

systemctl stop snmpd.service
systemctl mask snmpd.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure telnet server services are not in use

High severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Telnet server service is in use.

Checks that the telnet server service (inetutils-inetd.service serving telnetd) is masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: Telnet is unencrypted; anyone able to sniff traffic can capture credentials. The telnet server should not run.

Impact: Inbound telnet logins stop; use SSH instead.

Remediation

From the command line:

systemctl stop inetutils-inetd.service
systemctl mask inetutils-inetd.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure tftp server services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Tftp server service is in use.

Checks that the TFTP server service (tftpd-hpa.service) is masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: TFTP has no encryption, access control, or authentication; unless required (e.g. PXE boot) the TFTP server should not run.

Impact: TFTP file serving (including network boot support) stops.

Remediation

From the command line:

systemctl stop tftpd-hpa.service
systemctl mask tftpd-hpa.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure web proxy server services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Web proxy server service is in use.

Checks that the Squid web proxy service is masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: Unless the host is a designated proxy server, the squid service should not run so as to reduce attack surface.

Impact: Web proxying via squid stops.

Remediation

From the command line:

systemctl stop squid.service
systemctl mask squid.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure web server services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Web server service is in use.

Checks that the apache2 and nginx web server services/sockets are masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: Web servers add listening network services that process untrusted remote input and expose extra attack surface via modules; they should not run unless hosting web content.

Impact: The host can no longer serve web content from apache2 or nginx.

Remediation

From the command line:

systemctl stop apache2.socket apache2.service
systemctl mask apache2.socket apache2.service
systemctl stop nginx.service
systemctl mask nginx.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure X window server services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: X window server package is installed.

Checks that the X Window System server package (xserver-common) is not installed.

This rule fails when the installed package name is one of the prohibited packages.

Rationale: Servers typically do not need a graphical X session; removing the X server reduces attack surface.

Impact: Graphical X sessions become unavailable; a GDM in use may depend on this package and should be reviewed first.

Remediation

From the command line:

apt purge xserver-common
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure xinetd services are not in use

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.1

Finding: Xinetd service is in use.

Checks that the xinetd super-daemon service is masked or stopped.

This rule fails when the service unit is loaded (not masked) and RUNNING.

Rationale: xinetd launches on-demand network daemons; unless xinetd services are required it should not run so as to reduce attack surface.

Impact: Any services launched via xinetd will no longer start on demand.

Remediation

From the command line:

systemctl stop xinetd.service
systemctl mask xinetd.service
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

2.2 Configure Client Services

Ensure ftp client is not installed

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.2

Finding: Ftp client package is installed.

Checks that neither the ftp nor tnftp client package is installed.

This rule fails when the installed package name is one of the prohibited packages.

Rationale: FTP is a cleartext protocol; unless required, the FTP client should be removed to reduce attack surface.

Impact: The ftp/tnftp client commands become unavailable; use SFTP instead.

Remediation

From the command line:

apt purge ftp
apt purge tnftp
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure ldap client is not installed

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.2

Finding: Ldap client package is installed.

Checks that the ldap-utils client package is not installed.

This rule fails when the installed package name is one of the prohibited packages.

Rationale: If the host does not need to act as an LDAP client, removing ldap-utils reduces attack surface.

Impact: LDAP client utilities become unavailable, which may inhibit LDAP-based authentication.

Remediation

From the command line:

apt purge ldap-utils
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure nis client is not installed

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.2

Finding: Nis client package is installed.

Checks that the nis client package is not installed.

This rule fails when the installed package name is one of the prohibited packages.

Rationale: NIS is insecure (weak authentication, DoS/buffer-overflow history) and superseded by LDAP; the client should be removed to prevent misuse.

Impact: NIS client lookups become unavailable.

Remediation

From the command line:

apt purge nis
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure rsh client is not installed

High severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.2

Finding: Rsh client package is installed.

Checks that the rsh-client package (rsh, rcp, rlogin) is not installed.

This rule fails when the installed package name is one of the prohibited packages.

Rationale: The rsh family sends credentials in the clear and has numerous exposures; removing the client prevents users from inadvertently exposing credentials.

Impact: The rsh, rcp, and rlogin commands become unavailable; use SSH/SCP instead.

Remediation

From the command line:

apt purge rsh-client
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure talk client is not installed

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.2

Finding: Talk client package is installed.

Checks that the talk client package is not installed.

This rule fails when the installed package name is one of the prohibited packages.

Rationale: talk uses unencrypted protocols and presents a security risk; the client should be removed unless required.

Impact: The talk messaging command becomes unavailable.

Remediation

From the command line:

apt purge talk
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure telnet client is not installed

High severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.2

Finding: Telnet client package is installed.

Checks that neither the telnet nor inetutils-telnet client package is installed.

This rule fails when the installed package name is one of the prohibited packages.

Rationale: The telnet protocol is unencrypted; the client should be removed so credentials cannot be exposed over telnet. Use SSH instead.

Impact: The telnet client command becomes unavailable.

Remediation

From the command line:

apt purge telnet inetutils-telnet
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Credential Access (TA0006)

2.3 Configure Time Synchronization

Ensure systemd-timesyncd is enabled and running

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.3.2

Finding: systemd-timesyncd is not enabled and running.

Checks that systemd-timesyncd.service is enabled and active, treating a masked unit (chrony chosen instead) as compliant.

This rule fails when the time-sync service is neither masked nor enabled-and-running.

Rationale: Accurate, synchronized time underpins time-sensitive security controls and consistent log timestamps for forensics.

Impact: None; enables the system time synchronization client.

Remediation

From the command line:

systemctl unmask systemd-timesyncd.service
systemctl --now enable systemd-timesyncd.service
Framework mappings
  • CIS Controls v8: 8.4 Standardize Time Synchronization
  • NIST SP 800-53 Rev. 5: AU-8 Time Stamps; AU-12 Audit Record Generation
  • NIST SP 800-171 Rev. 2: 3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
  • CMMC 2.0 Level 2: AU.L2-3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
  • PCI DSS v4.0.1: 10.6.1 Deploy time-sync technology to align all system clocks; 10.6.2 Use designated central time servers for correct, consistent time; 10.6.3 Restrict who can reach time data and log time setting changes
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure chrony is enabled and running

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.3.3

Finding: Chrony is not enabled and running.

Checks that chrony.service is enabled and active, treating a masked unit (systemd-timesyncd chosen instead) as compliant.

This rule fails when the time-sync service is neither masked nor enabled-and-running.

Rationale: Accurate, synchronized time underpins time-sensitive security controls and consistent log timestamps for forensics.

Impact: None; enables the chrony time synchronization daemon.

Remediation

From the command line:

systemctl unmask chrony.service
systemctl --now enable chrony.service
Framework mappings
  • CIS Controls v8: 8.4 Standardize Time Synchronization
  • NIST SP 800-53 Rev. 5: AU-8 Time Stamps; AU-12 Audit Record Generation
  • NIST SP 800-171 Rev. 2: 3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
  • CMMC 2.0 Level 2: AU.L2-3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
  • PCI DSS v4.0.1: 10.6.1 Deploy time-sync technology to align all system clocks; 10.6.2 Use designated central time servers for correct, consistent time; 10.6.3 Restrict who can reach time data and log time setting changes
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure chrony is running as user _chrony

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.3.3

Finding: Chrony is not running as user _chrony.

Checks that the chrony time daemon runs under the dedicated _chrony account rather than root, using the service unit userName field.

This rule fails when chrony.service runs as a user other than _chrony.

Rationale: Running chronyd with only the required privileges limits the impact of a compromise of the time daemon.

Impact: None; chronyd continues to function under its dedicated account.

Remediation

From the command line:

# add or edit in /etc/chrony/chrony.conf (or a .conf drop-in under /etc/chrony/conf.d/):
# user _chrony
systemctl restart chrony.service
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

2.4 Job Schedulers

Ensure cron daemon is enabled and active

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 2.4.1

Finding: Cron daemon is not enabled and active.

Checks that the cron daemon (cron.service) is enabled and active so scheduled system and security maintenance jobs run.

This rule fails when cron.service is masked, disabled, or not RUNNING.

Rationale: Cron runs scheduled maintenance and security-monitoring jobs; if the daemon is not enabled and running those jobs will not execute.

Impact: None; ensures scheduled jobs continue to run.

Remediation

From the command line:

systemctl unmask cron.service
systemctl --now enable cron.service
Risk
Reliability Impact
MITRE ATT&CK tactic
Defense Evasion (TA0005)