Mozilla Firefox Security Technical Implementation Guide
Open a previous version of this SCAP benchmark.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001453
- Version
- DTBF030
- Vuln IDs
- V-223152
- Rule IDs
- SV-223152r612236_rule
Fix: F-24813r531274_fix
Configure the following parameters using the Mozilla.cfg file: LockPref "security.tls.version.min" is set to "2". LockPref "security.tls.version.max" is set to "4".
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000187
- Version
- DTBF050
- Vuln IDs
- V-223153
- Rule IDs
- SV-223153r612236_rule
Fix: F-24814r531277_fix
Set the value of "security.default_personal_cert" to "Ask Every Time". Use the Mozilla.cfg file to lock the preference so users cannot change it.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF085
- Vuln IDs
- V-223154
- Rule IDs
- SV-223154r612236_rule
Fix: F-24815r531280_fix
Ensure the preference "browser.search.update" is set and locked to the value of “False”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF090
- Vuln IDs
- V-223155
- Rule IDs
- SV-223155r612236_rule
Fix: F-24816r531283_fix
Set the preference “extensions.update.enabled” value to "false" and lock using the Mozilla.cfg file.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF105
- Vuln IDs
- V-223157
- Rule IDs
- SV-223157r612236_rule
Fix: F-24818r531289_fix
Procedure: Set the value of "network.protocol-handler.external.shell" to "false" and lock using the Mozilla.cfg file.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTBF110
- Vuln IDs
- V-223158
- Rule IDs
- SV-223158r612236_rule
Fix: F-24819r531292_fix
Ensure the following extensions are not automatically opened by Firefox without user confirmation. Do not use plugins and add-ons to open these files. Use the "plugin.disable_full_page_plugin_for_types" preference to set and lock the following extensions so that an external application, rather than an add-on or plugin, will not be used: PDF, FDF, XFDF, LSL, LSO, LSS, IQY, RQY, XLK, XLS, XLT, POT, PPS, PPT, DOS, DOT, WKS, BAT, PS, EPS, WCH, WCM, WB1, WB3, RTF, DOC, MDB, MDE, WBK, WB1, WCH, WCM, AD, ADP.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF140
- Vuln IDs
- V-223160
- Rule IDs
- SV-223160r612236_rule
Fix: F-24821r531298_fix
Ensure the preference “browser.formfill.enable" is set and locked to the value of “false”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF150
- Vuln IDs
- V-223161
- Rule IDs
- SV-223161r612236_rule
Fix: F-24822r531301_fix
Ensure the preference "signon.autofillForms" is set and locked to the value of “false”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF160
- Vuln IDs
- V-223162
- Rule IDs
- SV-223162r612236_rule
Fix: F-24823r531304_fix
Ensure the preference “signon.rememberSignons“ is set and locked to the value of “false”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF180
- Vuln IDs
- V-223163
- Rule IDs
- SV-223163r612236_rule
Fix: F-24824r531307_fix
Ensure the preference "dom.disable_window_open_feature.status " is set and locked to the value of “true”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF181
- Vuln IDs
- V-223164
- Rule IDs
- SV-223164r612236_rule
Fix: F-24825r531310_fix
Ensure the preference "dom.disable_window_move_resize" is set and locked to the value of “true”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF182
- Vuln IDs
- V-223165
- Rule IDs
- SV-223165r612236_rule
Fix: F-24826r531313_fix
Ensure the preference "dom.disable_window_flip" is set and locked to the value of “true”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF183
- Vuln IDs
- V-223166
- Rule IDs
- SV-223166r612236_rule
Fix: F-24827r531316_fix
Ensure the preferences "dom.event.contextmenu.enabled" is set and locked to "false".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF186
- Vuln IDs
- V-223167
- Rule IDs
- SV-223167r612236_rule
Fix: F-24828r531319_fix
Set the preference “xpinstall.enabled” to “false” and lock using the “mozilla.cfg” file. The “mozilla.cfg” file may need to be created if it does not already exist.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF190
- Vuln IDs
- V-223168
- Rule IDs
- SV-223168r612236_rule
Fix: F-24829r531322_fix
Ensure the preferences "datareporting.policy.dataSubmissionEnabled" is set and locked to "false".
- RMF Control
- SI-11
- Severity
- L
- CCI
- CCI-001312
- Version
- DTBF195
- Vuln IDs
- V-223169
- Rule IDs
- SV-223169r612236_rule
Fix: F-24830r531325_fix
Set the value of "devtools.policy.disabled" to "true" using the Mozilla.cfg file, or the registry value of HKLM\Software\Policies\Mozilla\Firefox\DisableDeveloperTools to “1”
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF200
- Vuln IDs
- V-223170
- Rule IDs
- SV-223170r612236_rule
Fix: F-24831r531328_fix
Ensure the preference “toolkit.telemetry.enabled" is set and locked to the value of “false”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF205
- Vuln IDs
- V-223171
- Rule IDs
- SV-223171r612236_rule
Fix: F-24832r531331_fix
Ensure the preference “toolkit.telemetry.archive.enabled" is set and locked to the value of “false”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF210
- Vuln IDs
- V-223172
- Rule IDs
- SV-223172r612236_rule
Fix: F-24833r531334_fix
Ensure the preference “privacy.trackingprotection.fingerprinting.enabled" is set and locked to the value of “true”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF215
- Vuln IDs
- V-223173
- Rule IDs
- SV-223173r612236_rule
Fix: F-24834r531337_fix
Ensure the preference “privacy.trackingprotection.cryptomining.enabled" is set and locked to the value of “true”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF220
- Vuln IDs
- V-223174
- Rule IDs
- SV-223174r612236_rule
Fix: F-24835r531340_fix
Ensure the preference “browser.contentblocking.category" is set and locked to the value of “strict”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF225
- Vuln IDs
- V-223175
- Rule IDs
- SV-223175r612236_rule
Fix: F-24836r531343_fix
Ensure the preference “extensions.htmlaboutaddons.recommendations.enabled" is set and locked to the value of “false”.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001453
- Version
- DTBF235
- Vuln IDs
- V-223177
- Rule IDs
- SV-223177r612236_rule
Fix: F-24838r531349_fix
Ensure the preference “security.ssl3.rsa_des_ede3_sha" is set and locked to the value of “false”.