SV-239259r674706_rule
V-239259
SRG-OS-000480-VMM-002000
ESXI-67-000002
CAT III
10
From the vSphere Client, select the ESXi host and go to Configure >> System >> Advanced System Settings.
Click "Edit", select the "DCUI.Access" value, and configure it to root.
or
From a PowerCLI command prompt while connected to the ESXi host, run the following command:
Get-VMHost | Get-AdvancedSetting -Name DCUI.Access | Set-AdvancedSetting -Value "root"
For environments that do not use vCenter server to manage ESXi, this is Not Applicable.
From the vSphere Client, select the ESXi host and go to Configure >> System >> Advanced System Settings.
Select the "DCUI.Access" value and verify that only the root user is listed.
or
From a PowerCLI command prompt while connected to the ESXi host, run the following command:
Get-VMHost | Get-AdvancedSetting -Name DCUI.Access and verify it is set to root.
If the DCUI.Access is not restricted to root, this is a finding.
Note: This list is only for local user accounts and should only contain the root user.
V-239259
False
ESXI-67-000002
For environments that do not use vCenter server to manage ESXi, this is Not Applicable.
From the vSphere Client, select the ESXi host and go to Configure >> System >> Advanced System Settings.
Select the "DCUI.Access" value and verify that only the root user is listed.
or
From a PowerCLI command prompt while connected to the ESXi host, run the following command:
Get-VMHost | Get-AdvancedSetting -Name DCUI.Access and verify it is set to root.
If the DCUI.Access is not restricted to root, this is a finding.
Note: This list is only for local user accounts and should only contain the root user.
M
5326