STIGQter STIGQter: STIG Summary: Trend Micro TippingPoint NDM Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Apr 2025:

The TippingPoint SMS must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.

DISA Rule

SV-242237r1051115_rule

Vulnerability Number

V-242237

Group Title

SRG-APP-000148-NDM-000346

Rule Version

TIPP-NM-000210

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the SMS client, ensure the SMS has only a single local emergency account.

1. Select Admin >> Authentication and Authorization >> Users.
2. Delete all but the user account being used for local emergency user account/account of last resort functions.

The local emergency user account must not be disabled after 35 days of inactivity. Log in to the serial console and set the following command:

set pwd.emergency-user=<USERNAME>

Check Contents

In the SMS client, ensure the SMS has only a single local account.

Select Admin >> Authentication and Authorization >> Users.

If more than one user is enabled under user accounts, this is a finding.

Vulnerability Number

V-242237

Documentable

False

Rule Version

TIPP-NM-000210

Severity Override Guidance

In the SMS client, ensure the SMS has only a single local account.

Select Admin >> Authentication and Authorization >> Users.

If more than one user is enabled under user accounts, this is a finding.

Check Content Reference

M

Target Key

5369