V-218750
CAT IAnonymous IIS 10.0 website access accounts must be restricted.
- Ships Affected
- 2
- Total Findings
- 4
- Open
- 0
- Closed
- 4
Check Text
Check the account used for anonymous access to the website.
Follow the procedures below for each site hosted on the IIS 10.0 web server:
Open the IIS 10.0 Manager.
Double-click "Authentication" in the IIS section of the website’s Home Pane.
If "Anonymous access" is disabled, this is Not a Finding.
If "Anonymous access" is enabled, click "Anonymous Authentication".
Click "Edit" in the "Actions" pane.
If the "Specific user" radio button is enabled and an ID is specified in the adjacent control box, this is the ID being used for anonymous access. Note the account name.
If nothing is tied to "Specific User", this is Not a Finding.
Check privileged groups that may allow the anonymous account inappropriate membership:
Open "Computer Management" on the machine.
Expand "Local Users and Groups".
Open "Groups".
Review the members of any of the following privileged groups:
Administrators
Backup Operators
Certificate Services (of any designation)
Distributed COM Users
Event Log Readers
Network Configuration Operators
Performance Log Users
Performance Monitor Users
Power Users
Print Operators
Remote Desktop Users
Replicator
Double-click each group and review its members.
If the IUSR account or any account noted above used for anonymous access is a member of any group with privileged access, this is a finding.
Fix Text
Remove the Anonymous access account from all privileged accounts and all privileged groups.
STIG Reference
- STIG
- Microsoft IIS 10.0 Site Security Technical Implementation Guide
- Version
- 2
- Release
- 15
- Rule ID
- SV-218750r1138073_rule
All Occurrences
This vulnerability appears on 2 ship(s)
| Ship | Hull # | Source File | Status | Assigned To | Scan Date | Actions |
|---|---|---|---|---|---|---|
| LAB BASELINES | BASELINE | SCHR-P3-DP-001_IIS10Site_Default_Web_Site_V2R14_20260305-133115.cklb | Unassigned | 2026-03-12T15:38:14.459023 | View in Context | |
| USNS MONTFORD POINT | T-ESD-1 | _Reviewed/MONT-DP-001/Checklist/MONT-DP-001_IIS10Site_Default_Web_Site_V2R12_20251023-143912.ckl | Unassigned | 2026-01-14T12:57:35.375369 | View in Context | |
| USNS MONTFORD POINT | T-ESD-1 | _Reviewed/MONT-MB-002/Checklist/MONT-MB-002_IIS10Site_Exchange_Back_End_V2R12_20251023-152602.ckl | Unassigned | 2026-01-14T12:57:33.300070 | View in Context | |
| USNS MONTFORD POINT | T-ESD-1 | _Reviewed/MONT-MB-002/Checklist/MONT-MB-002_IIS10Site_Default_Web_Site_V2R12_20251023-152518.ckl | Unassigned | 2026-01-14T12:57:33.098574 | View in Context |