STIGQter STIGQter: STIG Summary: VMware NSX-T Manager NDM Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 26 Jul 2023:

The NSX-T Manager must disable unused local accounts.

DISA Rule

SV-251797r879588_rule

Vulnerability Number

V-251797

Group Title

SRG-APP-000142-NDM-000245

Rule Version

TNDM-3X-000100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the NSX-T Manager web interface, go to the System >> Users and Roles >> Local Users.

Select the menu drop down next to the user to modify and click "Deactivate User".

Check Contents

If NSX-T is not at least version 3.1.1, this is not applicable.

From the NSX-T Manager web interface, go to the System >> Users and Roles >> Local Users and view the status column.

If the audit, guestuser1, or guestuser2 local accounts are active, this is a finding.

Vulnerability Number

V-251797

Documentable

False

Rule Version

TNDM-3X-000100

Severity Override Guidance

If NSX-T is not at least version 3.1.1, this is not applicable.

From the NSX-T Manager web interface, go to the System >> Users and Roles >> Local Users and view the status column.

If the audit, guestuser1, or guestuser2 local accounts are active, this is a finding.

Check Content Reference

M

Target Key

5449