---
title: Network Services Security Controls: 13 Checks | Wartiva
description: The 13 checks Wartiva runs for network services, beyond the CIS Benchmarks: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/wartiva/network-services.html
updated: 2026-10-07
---

Wartiva Security Controls

# Network Services: 13 Checks

Wartiva's Network Services controls: network services your endpoints and devices expose, from SSH, SMB, and SNMP to Telnet, FTP, and rogue DHCP servers, plus known vulnerabilities in them.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## SSH services

### [Ensure SSH Servers Are Not Insecurely Configured](https://wartiva.com/policy-rules/wartiva/network-services.html#ssh-servers-are-not-insecurely-configured)

High severity · Wartiva Security Controls · Network Services

**Finding:** An SSH server offers insecure protocol, key-exchange, host-key, cipher, or MAC algorithms.

This rule inspects a discovered SSH service's negotiated algorithms. This rule fails when the SSH protocol version is 1.x, or the server offers a weak key-exchange, host-key, cipher, or MAC algorithm (e.g. `diffie-hellman-group1-sha1`, `ssh-rsa`/`ssh-dss`, CBC/3DES/RC4 ciphers, or MD5/short MACs).

**Rationale:** SSHv1 and these legacy algorithms are cryptographically broken or deprecated and enable downgrade, key-recovery, or MITM attacks.

**Impact:** An attacker on the network path can compromise the confidentiality or integrity of SSH sessions and administrative credentials.

#### Remediation

Reconfigure the SSH server to disable protocol 1 and remove weak algorithms. Restrict KexAlgorithms, HostKeyAlgorithms, Ciphers, and MACs to modern values (curve25519/ECDH, ed25519/rsa-sha2, AES-GCM/ChaCha20, HMAC-SHA2), then restart the SSH service.

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risks

Insecure Application, Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## SMB file-sharing services

### [Ensure SMB Services Are Not Insecurely Configured](https://wartiva.com/policy-rules/wartiva/network-services.html#smb-services-are-not-insecurely-configured)

High severity · Wartiva Security Controls · Network Services

**Finding:** An SMB service allows SMBv1, share-level or no authentication, or has message signing disabled.

This rule inspects a discovered SMB service. This rule fails when SMBv1 is supported (`supportV1`), authentication is unset, share-level authentication is used (`authenticationLevel == SHARE`), or SMB message signing is disabled (`messageSigning == DISABLED`).

**Rationale:** SMBv1 is obsolete and wormable (EternalBlue), share-level/absent authentication grants broad access, and unsigned SMB is vulnerable to relay and tampering.

**Impact:** These weaknesses enable unauthorized access, credential relay, and adversary-in-the-middle attacks against file sharing.

#### Remediation

Disable SMBv1, require user-level authentication, and require SMB message signing on the server, then restart the service.

- **Windows server:** remove the SMB1 feature and set SMB signing to Required through Group Policy.
- **Samba (Linux or macOS):** set `server min protocol = SMB2` and `server signing = mandatory` in the Samba configuration.

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risks

Insecure Application, Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## SMTP mail services

### [Ensure SMTP Servers Require TLS And Are Not Open Relays](https://wartiva.com/policy-rules/wartiva/network-services.html#smtp-servers-require-tls-and-are-not-open-relays)

High severity · Wartiva Security Controls · Network Services

**Finding:** An SMTP server has TLS disabled or is operating as an open relay.

This rule inspects a discovered SMTP service. This rule fails when the server does not support TLS (`tlsSupport == false`) or is an open relay (`isOpenRelay == true`).

**Rationale:** Mail sent without TLS is exposed in transit, and an open relay lets anyone send mail through the server.

**Impact:** Cleartext SMTP exposes message contents and credentials; an open relay enables spam, phishing, and reputation damage.

#### Remediation

Enable STARTTLS/implicit TLS on the mail server and require it for message submission. Disable open relaying by restricting relay to authenticated users and known networks. Restart the mail service.

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risks

Insecure Application, Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## SNMP management services

### [Ensure SNMP Services Do Not Use Default Community Strings](https://wartiva.com/policy-rules/wartiva/network-services.html#snmp-services-do-not-use-default-community-strings)

High severity · Wartiva Security Controls · Network Services

**Finding:** An SNMP service uses a default community string (public/private).

This rule inspects a discovered SNMP service's community strings. This rule fails when any community name is a well-known default (`public` or `private`).

**Rationale:** Default community strings act as guessable, cleartext credentials granting read (or write) access to device management data.

**Impact:** Attackers can enumerate detailed system information and, with a writable community, alter device configuration.

#### Remediation

Replace default SNMP community strings with strong, unique values, and prefer SNMPv3 with authentication and privacy. Restrict SNMP access to trusted management hosts. Restart the SNMP service.

Framework mappings

- **CIS Controls v8**: 4.7 Manage Default Accounts on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: IA-5 Authenticator Management
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 2.3.1 Replace or confirm default wireless settings when installing access points

Risks

Insecure Use of Secrets, Unprotected Data

MITRE ATT&CK tactic

Reconnaissance ([TA0043](https://attack.mitre.org/tactics/TA0043/))

## NTP time services

### [Ensure NTP Servers Do Not Respond To Monlist Queries](https://wartiva.com/policy-rules/wartiva/network-services.html#ntp-servers-do-not-respond-to-monlist-queries)

Medium severity · Wartiva Security Controls · Network Services

**Finding:** An NTP server responds to monlist queries (amplification vulnerability).

This rule inspects a discovered NTP service. This rule fails when the server responds to the legacy `monlist` query (`monlistResponded == true`).

**Rationale:** The `monlist` command returns a large response to a small request, making the server usable as a DDoS amplifier (CVE-2013-5211), and leaks recent client addresses.

**Impact:** The server can be abused to amplify denial-of-service attacks against third parties and discloses network reconnaissance data.

#### Remediation

Stop the NTP server answering the legacy `monlist` (mode 6/7) queries, then restart the NTP service.

- **ntpd (Linux, macOS, or BSD):** upgrade to 4.2.7p26 or later, or add `disable monitor` to the ntpd configuration. chrony doesn't answer `monlist` and is a safe replacement.
- **Network appliance:** update to firmware that no longer answers `monlist`.

Risk

External Attack Surface

MITRE ATT&CK tactic

Reconnaissance ([TA0043](https://attack.mitre.org/tactics/TA0043/))

## FTP file-transfer services

### [Ensure Cleartext FTP Services Are Not Present](https://wartiva.com/policy-rules/wartiva/network-services.html#cleartext-ftp-services-are-not-present)

Medium severity · Wartiva Security Controls · Network Services

**Finding:** A cleartext FTP service is present on the network.

This rule inspects discovered services for cleartext FTP. This rule fails when a service of type FTP is present.

**Rationale:** FTP transmits credentials and data in cleartext and has weak session handling.

**Impact:** Credentials and transferred files can be intercepted on the network path.

#### Remediation

Decommission the FTP service and replace it with SFTP (SSH) or FTPS (FTP over TLS). If FTP must remain, restrict it to an isolated network and require TLS.

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; CM-6 Configuration Settings; CM-7 Least Functionality; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 6.4.1 Assess or shield public-facing web applications against known attacks; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risks

Insecure Application, Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## Telnet remote-access services

### [Ensure Cleartext Telnet Services Are Not Present](https://wartiva.com/policy-rules/wartiva/network-services.html#cleartext-telnet-services-are-not-present)

High severity · Wartiva Security Controls · Network Services

**Finding:** A cleartext Telnet service is present on the network.

This rule inspects discovered services for Telnet. This rule fails when a service of type Telnet is present.

**Rationale:** Telnet transmits credentials and all session data in cleartext and provides no integrity protection.

**Impact:** Administrative credentials and session contents can be intercepted or hijacked on the network path.

#### Remediation

Disable the Telnet service and use SSH for remote administration.

- **Windows:** remove the Telnet Server feature.
- **Linux or macOS:** uninstall the Telnet server package and remove its inetd or xinetd entry.
- **Network device:** turn Telnet off in the device's management settings and turn SSH on.

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; CM-6 Configuration Settings; CM-7 Least Functionality; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 6.4.1 Assess or shield public-facing web applications against known attacks; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risks

Insecure Application, Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## Network printing services (IPP, AppSocket, raw ports)

### [Ensure AppSocket Printer Services Are Not Present](https://wartiva.com/policy-rules/wartiva/network-services.html#appsocket-printer-services-are-not-present)

Medium severity · Wartiva Security Controls · Network Services

**Finding:** An AppSocket (JetDirect) printer service is present on the network.

This rule inspects discovered services for AppSocket/JetDirect (raw port 9100) printing. This rule fails when a service of type AppSocket is present.

**Rationale:** AppSocket/JetDirect printing is unauthenticated and cleartext, allowing document interception and print-job injection.

**Impact:** Documents sent to the printer can be eavesdropped and the printer can be abused by anyone with network access.

#### Remediation

Disable raw AppSocket/JetDirect (port 9100) printing and use an authenticated, encrypted printing protocol such as IPPS. Restrict printer access to trusted print servers.

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure IPP Print Services Have TLS Enabled](https://wartiva.com/policy-rules/wartiva/network-services.html#ipp-print-services-have-tls-enabled)

Medium severity · Wartiva Security Controls · Network Services

**Finding:** An IPP print service has TLS disabled.

This rule inspects a discovered IPP (Internet Printing Protocol) service. This rule fails when the service does not support TLS (`tlsSupport == false`).

**Rationale:** Without TLS, print jobs and IPP credentials traverse the network in cleartext.

**Impact:** Document contents and authentication data sent to the printer can be intercepted.

#### Remediation

Enable TLS (IPPS) on the print server and require encrypted connections for printing. Restart the print service.

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risk

Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Raw Printer Ports (TCP 9100) Are Not Open](https://wartiva.com/policy-rules/wartiva/network-services.html#raw-printer-ports-tcp-9100-are-not-open)

Low severity · Wartiva Security Controls · Network Services

**Finding:** TCP port 9100 is open and suspected to be a raw (AppSocket/JetDirect) printer service.

This rule inspects open TCP ports. This rule fails when TCP port 9100 is open. Because port 9100 cannot be safely probed for a banner, any host with it open is treated as a suspected raw (AppSocket/JetDirect) print service.

**Rationale:** Raw port 9100 printing is unauthenticated and cleartext, allowing document interception and print-job injection. An open 9100 that is not a known print service may also be an unexpected listener worth investigating.

**Impact:** Documents sent to the printer can be eavesdropped and the printer can be abused by anyone with network access; an unexpected listener may indicate misconfiguration or compromise.

#### Remediation

Confirm whether the host with TCP port 9100 open is an authorized printer or print server. If it is a printer, disable raw AppSocket/JetDirect (port 9100) printing and use an authenticated, encrypted printing protocol such as IPPS, and restrict access to trusted print servers. If the host is not a printer, treat the open port as an unexpected listener and investigate.

Risk

Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## IRC chat services

### [Ensure IRC Services Are Not Present](https://wartiva.com/policy-rules/wartiva/network-services.html#irc-services-are-not-present)

Medium severity · Wartiva Security Controls · Network Services

**Finding:** An IRC service is present on the network.

This rule inspects discovered services for IRC (Internet Relay Chat). This rule fails when a service of type IRC is present.

**Rationale:** IRC is rarely used for legitimate business purposes on modern networks and is a common command-and-control channel for botnets and malware.

**Impact:** An unexpected IRC service can indicate a compromised host or an unmonitored communication channel that bypasses security controls.

#### Remediation

Identify the host running the IRC service and confirm whether it is authorized. If it is not expected, treat the host as potentially compromised: isolate it, investigate for malware or command-and-control activity, and remove the service.

Risks

Insecure Application, High Profile Threat

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## DHCP servers, including unauthorized (rogue) ones

### [Ensure Each Network Has Only One DHCP Server](https://wartiva.com/policy-rules/wartiva/network-services.html#each-network-has-only-one-dhcp-server)

High severity · Wartiva Security Controls · Network Services

**Finding:** This DHCP server shares its network with another DHCP server.

This rule counts the DHCP servers on each DHCP server's network. This rule fails for each server whose network has more than one, so every server on a contested network is flagged, including the one that doesn't belong.

**Rationale:** A network normally runs one DHCP server, or a failover pair. An unexpected DHCP server can hand clients an attacker's gateway or DNS server.

**Impact:** Clients that take a lease from a rogue server send their traffic through the attacker, who can intercept, modify, or redirect it.

**Note:** A server that has left the network keeps counting until data retention removes it.

#### Remediation

Compare the DHCP servers on this network with the ones you run. Physically locate and remove any server that isn't yours, and enable DHCP snooping on your switches so only trusted ports can answer DHCP requests. If you run a failover pair on purpose, accept the findings for those two servers.

Risks

High Profile Threat, Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## Known vulnerabilities in discovered network services

### [Ensure Network Services Have No High-Severity Vulnerabilities](https://wartiva.com/policy-rules/wartiva/network-services.html#network-services-have-no-high-severity-vulnerabilities)

High severity · Wartiva Security Controls · Network Services

**Finding:** This network service has one or more high or critical severity vulnerabilities.

This rule matches the software identified on each discovered network service against known vulnerabilities (CVEs). This rule fails for a service with one or more vulnerabilities rated high or critical, and records the most severe, with the total matched, in one finding.

**Rationale:** A vulnerable network service is reachable by anyone who can reach the network, often without credentials.

**Impact:** Remote exploitation of the service can compromise the device and give an attacker a foothold in the network.

#### Remediation

Update or patch the service's software to a version that fixes the listed CVEs, starting with any marked as known exploited. Where that isn't possible, restrict network access to the service or disable it.

Framework mappings

- **CIS Controls v8**: 7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets; 7.7 Remediate Detected Vulnerabilities
- **NIST SP 800-53 Rev. 5**: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- **NIST SP 800-171 Rev. 2**: 3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified; 3.11.3 Remediate vulnerabilities in accordance with risk assessments; 3.14.1 Identify, report, and correct system flaws in a timely manner
- **CMMC 2.0 Level 1**: SI.L1-b.1.xii Identify, report, and correct information and information system flaws in a timely manner
- **CMMC 2.0 Level 2**: RA.L2-3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified; RA.L2-3.11.3 Remediate vulnerabilities in accordance with risk assessments; SI.L2-3.14.1 Identify, report, and correct system flaws in a timely manner
- **PCI DSS v4.0.1**: 11.3.1.1 Address lower-risk vulnerabilities as set by targeted risk analysis; 11.3.1.2 Run credentialed internal scans using adequate privileges; 11.3.1.3 Rescan internally after significant changes and resolve high-risk findings; 11.3.2.1 Run external scans after significant changes and fix CVSS 4.0+ findings

Risk

Vulnerability

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
