STIGQter STIGQter: STIG Summary: HPE Nimble Storage Array NDM Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The HPE Nimble must require that when a password is changed, the characters are changed in at least eight of the positions within the password.

DISA Rule

SV-252195r997779_rule

Vulnerability Number

V-252195

Group Title

SRG-APP-000170-NDM-000329

Rule Version

HPEN-NM-000100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Set minimum number of characters changed from previous password to 8 by typing "userpolicy --edit --previous_diff 8".

Check Contents

Type "userpolicy --info" and review output for line: "Minimum number of characters change from previous password".

If it is 8 or more, this is not a finding.

Vulnerability Number

V-252195

Documentable

False

Rule Version

HPEN-NM-000100

Severity Override Guidance

Type "userpolicy --info" and review output for line: "Minimum number of characters change from previous password".

If it is 8 or more, this is not a finding.

Check Content Reference

M

Target Key

5460