STIGQter STIGQter: STIG Summary: Infoblox 8.x DNS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 09 Jan 2021:

The Infoblox NIOS version must be at the appropriate version.

DISA Rule

SV-233875r621666_rule

Vulnerability Number

V-233875

Group Title

SRG-APP-000516-DNS-000103

Rule Version

IDNS-8X-400017

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Refer to the Infoblox NIOS Administrator Guide if necessary.

1. Log on to the Infoblox support portal and download the current version of NIOS.
2. Perform a Grid upgrade.

Check Contents

Infoblox systems use a modified version of BIND DNS software, which adds features and addresses security issues outside of those provided by ISC. Infoblox systems are provided as a hardened appliance and do not allow user access or upgrading of any software components, including BIND. The Infoblox support portal and release notes are the authoritative sources to validate version and applicability of vulnerabilities.

1. Verify the NIOS version by reviewing the "Grid, Upgrade" tab to show that all members are at the current version.
2. Use the Infoblox support portal to obtain current version information.

If the Infoblox NIOS version is not currently under support maintenance or is not at the current approved version level, this is a finding.

Vulnerability Number

V-233875

Documentable

False

Rule Version

IDNS-8X-400017

Severity Override Guidance

Infoblox systems use a modified version of BIND DNS software, which adds features and addresses security issues outside of those provided by ISC. Infoblox systems are provided as a hardened appliance and do not allow user access or upgrading of any software components, including BIND. The Infoblox support portal and release notes are the authoritative sources to validate version and applicability of vulnerabilities.

1. Verify the NIOS version by reviewing the "Grid, Upgrade" tab to show that all members are at the current version.
2. Use the Infoblox support portal to obtain current version information.

If the Infoblox NIOS version is not currently under support maintenance or is not at the current approved version level, this is a finding.

Check Content Reference

M

Target Key

5251

Comments