info: name: Linux Root Remote Login - Security Misconfiguration author: songyaeji severity: critical description:> Allowing remote access via Telnet or SSH for the root account poses a serious security risk. This template checks the configuration of /etc/securetty and sshd_config to determine whether root login is permitted. reference: - https://isms.kisa.or.kr/main/csap/notice/ - Cloud Vulnerability Assessment Guide(2024) by KISA tags: linux,ssh,root,misconfiguration,local metadata: verified:true os: linux max-request:2 classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score:9.8 cwe-id: CWE-306