CME-902

Disable Unused Network Services

Description

Disables and masks unnecessary listening services (rpcbind, avahi-daemon, cups, postfix on non-mail servers). Each removed service eliminates an attack surface.

CVSS Vector Impacts

Metric Transition Rationale
Attack Vector (AV) N L Fewer network-accessible services means fewer remote attack vectors

CWE Relationships

Verification

List listening services and verify only necessary ones are active

$ ss -tlnp | grep -v '127.0.0.1\|::1'
# Expected: Only expected services
Platform: linux

References

← CME-901: SSH Hardening (Comprehensive) CME-903: Kernel Network Hardening (sysctl) →