info: name: /etc/(x)inetd.conf File Owner and Permission Check author: songyaeji severity: high description: > If the /etc/xinetd.conf or /etc/inetd.conf file is writable by non-root users, they may register malicious services that run with root privileges. This check ensures the file is owned by root and has secure permissions. reference: - https://isms.kisa.or.kr/main/csap/notice/ - Cloud Vulnerability Assessment Guide (2024) by KISA tags: linux,local,configuration,file,ownership,permission,xinetd,inetd metadata: verified: true os: linux max-request: 2 classification: cwe-id: CWE-732 cvss-metrics: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H cvss-score: 7.4