CME-902
Disable Unused Network Services
Description
Disables and masks unnecessary listening services (rpcbind, avahi-daemon, cups, postfix on non-mail servers). Each removed service eliminates an attack surface.
CVSS Vector Impacts
| Metric | Transition | Rationale |
|---|---|---|
| Attack Vector (AV) | N → L | Fewer network-accessible services means fewer remote attack vectors |
CWE Relationships
Verification
List listening services and verify only necessary ones are active
$ ss -tlnp | grep -v '127.0.0.1\|::1'
# Expected: Only expected services
# Expected: Only expected services
Platform: linux