Skip to main content

Storage / File Storage / Threats / DEV

Unauthorized NFS Mount Access is Permitted

CCC.FileStor.TH01

Network access rules or mount configuration may allow clients outside the intended virtual network scope to mount the file system over NFS. Mount requests from unauthorized clients are accepted and read-write access to the shared namespace is granted. This impacts confidentiality and integrity of stored file content and may affect availability through unauthorized modification or deletion.

Related Capabilities

IDTitleDescription
CCC.FileStor.CP02NFS Protocol Mount AccessThe service always supports mounting the file system from compute instances using the Network File System (NFS) protocol over the provider network.
CCC.FileStor.CP03Private Network Mount AccessThe service can restrict mount and data-plane access to clients within designated virtual network subnets or private connectivity endpoints.
CCC.Core.CP06Access ControlThe service automatically enforces user configurations to restrict or allow access to a specific component or a child resource based on factors such as user identities, roles, groups, or attributes.
CCC.Core.CP23Network Access RulesThe service restricts access to child or networked resources based on user-defined network parameters such as IP address, protocol, port, or source.

Related Controls

IDTitleDescription
CCC.FileStor.CN01Restrict NFS Mount to Approved Network SourcesEnsure that NFS mount and data-plane access is limited to explicitly approved virtual network sources within the organizational trust perimeter.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1039Data from Network Shared Drive
MITRE-ATT&CKT1020Automated Exfiltration
D3FENDD3-NINetwork Isolation — counters T1039, T1020