STIGQter STIGQter: STIG Summary: Forescout Network Device Management Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 20 Nov 2020:

Forescout must be configured with only one web account and one CLI account of last resort with limited access and used only when the authentication server is unavailable.

DISA Rule

SV-230932r615886_rule

Vulnerability Number

V-230932

Group Title

SRG-APP-000148-NDM-000346

Rule Version

FORE-NM-000030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

There are two default accounts. The CLIAdmin root account can only be used with the CLI. To access the CLI, an account must be created that only has access to the CLI. Accounts created in CounterACT user profile in the web management tools do not have access to login to the CLI. The default console account "Admin" allows access to the web management tool. These accounts can be used as the accounts of last resort or two other accounts may be created for this purpose as long as a strong password that meets DoD requirements is used for both.

1. Log on to the Forescout Administrator UI.
2. From the menu, select Tools >> Options >> CounterACT user profiles.

Remove unauthorized local accounts not identified as the account of last resort.

Check Contents

Verify only one local account exists and that it has full administrator privileges.

1. Log on to the Forescout Administrator UI.
2. From the menu, select Tools >> Options >> CounterACT User Profiles.

If local accounts in the CounterACT User profile or CLI exist other than the accounts of last resort, this is a finding.

Vulnerability Number

V-230932

Documentable

False

Rule Version

FORE-NM-000030

Severity Override Guidance

Verify only one local account exists and that it has full administrator privileges.

1. Log on to the Forescout Administrator UI.
2. From the menu, select Tools >> Options >> CounterACT User Profiles.

If local accounts in the CounterACT User profile or CLI exist other than the accounts of last resort, this is a finding.

Check Content Reference

M

Target Key

5245

Comments