Aqua CSPM

Connect Serial Ports Disabled

Quick Info

Plugin TitleConnect Serial Ports Disabled
CloudGOOGLE
CategoryCompute
DescriptionEnsures connecting to serial ports is not enabled for VM instances
More InfoThe serial console does not allow restricting IP Addresses, which allows any IP address to connect to instance and should therefore be disabled.
GOOGLE Linkhttps://cloud.google.com/compute/docs/instances/interacting-with-serial-console
Recommended ActionEnsure the Enable Connecting to Serial Ports option is disabled for all compute instances.

Detailed Remediation Steps

  1. Log into the Google Cloud Platform Console.
  2. Scroll down the left navigation panel and choose the “Compute Engine” to select the “VM Instances” option.
  3. On the “VM Instances” page, select the VM instance which needs to be verified.
  4. On the “VM instance details” page, scroll down and check “Enable connecting to serial ports” is enabled or not for VM instances.
  5. Repeat steps number 2 - 4 to verify other VM instances in the network.
  6. Navigate to “Compute Engine”, choose the “VM instances” and select the “VM instance” which needs to disabled “Connecting to serial ports” for VM instances.
  7. On the “VM instance details” page, select the “Edit” button at the top.
  8. On the “VM instance details - Edit page”, unselect the checkbox next to “Enable connecting to serial ports."
  9. Click on the “Save” button to make the changes.
  10. Repeat steps number 6 - 9 to ensure the “Enable Connecting to Serial Ports” option is disabled for all compute instances.