STIGQter STIGQter: STIG Summary: HP FlexFabric Switch NDM Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 24 Jul 2020:

The HP FlexFabric Switch must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.

DISA Rule

SV-80689r1_rule

Vulnerability Number

V-66199

Group Title

SRG-APP-000142-NDM-000245

Rule Version

HFFS-ND-000046

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable unsecure protocols and services on the HP FlexFabric Switch:

[HP] undo ftp server enable
[HP] undo telnet server enable

Note: By default, both FTP and Telnet services are disabled.

Check Contents

Check if unsecured protocols and services are disabled on the HP FlexFabric Switch:

[HP] display ftp-server

FTP is not configured.

[HP] display current-configuration | include telnet

Note: When Telnet server is enabled, the output for this command is telnet server enable.

If all unnecessary and non-secure functions, ports, protocols, and services are not disabled, this is a finding.

Vulnerability Number

V-66199

Documentable

False

Rule Version

HFFS-ND-000046

Severity Override Guidance

Check if unsecured protocols and services are disabled on the HP FlexFabric Switch:

[HP] display ftp-server

FTP is not configured.

[HP] display current-configuration | include telnet

Note: When Telnet server is enabled, the output for this command is telnet server enable.

If all unnecessary and non-secure functions, ports, protocols, and services are not disabled, this is a finding.

Check Content Reference

M

Target Key

2971

Comments