STIGQter STIGQter: STIG Summary: HPE Nimble Storage Array NDM Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The HPE Nimble must be running an operating system release that is currently supported by the vendor.

DISA Rule

SV-252200r961863_rule

Vulnerability Number

V-252200

Group Title

SRG-APP-000516-NDM-000351

Rule Version

HPEN-NM-000150

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

To upgrade to a supported version, type "software --list".

Select the last version listed with at least number 5.2.x.

Type "software --download <version<, where <version< is the version selected.

After the download is complete, type "software --update" and accept the terms and conditions.

The update progress can be monitored using "software --update_status". Once finished, use "version" to verify that the new software has been installed correctly.

Check Contents

Log in to https://infosight.hpe.com using HPE Passport credentials.

Click on the Main Menu icon in the upper left corner. Select Resources >> Alletra 6000, Nimble Storage >> Documentation.

Determine current array OS version using User Interface (UI).

Refer to Nimble "GUI Administration Guide" Version: NOS 5.2.x, section "Hardware and Software Updates", subsection "Find the Array OS Version" to determine the version of the OS that is currently in use by the array.

Determine available array OS update versions using InfoSight.

*Any version of Nimble OS software greater than the "current array OS version" might qualify to be an update to the "current array OS version". The option exists to bypass several releases to come up to the newest available release depending upon requirements.

*Call HPE Support with any questions about choosing an appropriate release or the process to upgrade a release.

- Follow above instructions to log in to HPE InfoSight.
- Choose a "Software Version" from the left panel equal to or greater than the current array OS version. For example, 5.2.x would be equal to the current version and 5.3.x would be greater than the current version.
- Open the Release Notes document for each version that is greater than the current array OS version. For example, "NimbleOS Release Notes Version NOS 5.2.1.700" is greater than NOS 5.2.1.600.
- Review the entire release notes document.
- Determine if this is a release should be used for an upgrade.
- Confirm that the "From Version", for example 5.2.1.600, can be used to go to the version for which the release notes are applicable; for example 5.2.1.700.

If the operating system version is no longer supported by the vendor, this is a finding.

Vulnerability Number

V-252200

Documentable

False

Rule Version

HPEN-NM-000150

Severity Override Guidance

Log in to https://infosight.hpe.com using HPE Passport credentials.

Click on the Main Menu icon in the upper left corner. Select Resources >> Alletra 6000, Nimble Storage >> Documentation.

Determine current array OS version using User Interface (UI).

Refer to Nimble "GUI Administration Guide" Version: NOS 5.2.x, section "Hardware and Software Updates", subsection "Find the Array OS Version" to determine the version of the OS that is currently in use by the array.

Determine available array OS update versions using InfoSight.

*Any version of Nimble OS software greater than the "current array OS version" might qualify to be an update to the "current array OS version". The option exists to bypass several releases to come up to the newest available release depending upon requirements.

*Call HPE Support with any questions about choosing an appropriate release or the process to upgrade a release.

- Follow above instructions to log in to HPE InfoSight.
- Choose a "Software Version" from the left panel equal to or greater than the current array OS version. For example, 5.2.x would be equal to the current version and 5.3.x would be greater than the current version.
- Open the Release Notes document for each version that is greater than the current array OS version. For example, "NimbleOS Release Notes Version NOS 5.2.1.700" is greater than NOS 5.2.1.600.
- Review the entire release notes document.
- Determine if this is a release should be used for an upgrade.
- Confirm that the "From Version", for example 5.2.1.600, can be used to go to the version for which the release notes are applicable; for example 5.2.1.700.

If the operating system version is no longer supported by the vendor, this is a finding.

Check Content Reference

M

Target Key

5460