STIGQter STIGQter: STIG Summary: HP FlexFabric Switch NDM Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 24 Jul 2020:

The HP FlexFabric Switch must allow the use of a temporary password for system logons with an immediate change to a permanent password.

DISA Rule

SV-80747r1_rule

Vulnerability Number

V-66257

Group Title

SRG-APP-000397-NDM-000312

Rule Version

HFFS-ND-000113

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the HP FlexFabric Switch to allow the use of a temporary password for system logons with an immediate change to a permanent password.

[HP] password-control enable

Note: Once password control feature is enabled, user is forced to change password upon next logon.

Check Contents

Determine if the HP FlexFabric Switch allows the use of a temporary password for system logons with an immediate change to a permanent password. This requirement may be verified by demonstration, configuration review, or validated test results. This requirement may be met through use of a properly configured authentication server if the device is configured to use the authentication server.

[HP] display password-control

Global password control configurations:
Password control: Enabled

If the use of a temporary password for system logons with an immediate change to a permanent password is not allowed, this is a finding.

Vulnerability Number

V-66257

Documentable

False

Rule Version

HFFS-ND-000113

Severity Override Guidance

Determine if the HP FlexFabric Switch allows the use of a temporary password for system logons with an immediate change to a permanent password. This requirement may be verified by demonstration, configuration review, or validated test results. This requirement may be met through use of a properly configured authentication server if the device is configured to use the authentication server.

[HP] display password-control

Global password control configurations:
Password control: Enabled

If the use of a temporary password for system logons with an immediate change to a permanent password is not allowed, this is a finding.

Check Content Reference

M

Target Key

2971

Comments