The HPE Nimble must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes.
DISA Rule
SV-252187r960840_rule
Vulnerability Number
V-252187
Group Title
SRG-APP-000065-NDM-000214
Rule Version
HPEN-NM-000020
Severity
CAT II
CCI(s)
- CCI-000044 - Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period.
Weight
10
Fix Recommendation
Type "userpolicy --edit --allowed_attempts 2".
Check Contents
Type "userpolicy --info" and review output for line: "Number of authentication attempts". If the value is 2 or less, this is not a finding.
Vulnerability Number
V-252187
Documentable
False
Rule Version
HPEN-NM-000020
Severity Override Guidance
Type "userpolicy --info" and review output for line: "Number of authentication attempts". If the value is 2 or less, this is not a finding.
Check Content Reference
M
Target Key
5460