STIGQter STIGQter: STIG Summary: Juniper EX Series Switches Network Device Management Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The Juniper EX switch must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password.

DISA Rule

SV-253909r1082956_rule

Vulnerability Number

V-253909

Group Title

SRG-APP-000170-NDM-000329

Rule Version

JUEX-NM-000320

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the network device and associated authentication server to require that when a password is changed, the characters are changed in at least eight of the positions within the password.

set system login password minimum-character-changes 8

Note: For older Juniper EX versions, only four characters may be changed instead of the DOD-required eight characters. If so, four characters should be selected. This remains a finding when set to four characters, but is mitigated to a CAT 3.

Check Contents

For older Juniper EX versions, only four characters may be changed instead of the DOD-required eight characters. If so, four characters should be selected. This remains a finding when set to four characters, but is mitigated to a CAT 3.

Where passwords are used, confirm the characters are changed in at least eight of the positions within the password. This requirement may be verified by demonstration, configuration review, or validated test results.

[edit system login password]
:
minimum-character-changes 8;
:

If the network device and associated authentication server does not require that when a password is changed, the characters are changed in at least eight of the positions within the password, this is a finding.

Vulnerability Number

V-253909

Documentable

False

Rule Version

JUEX-NM-000320

Severity Override Guidance

For older Juniper EX versions, only four characters may be changed instead of the DOD-required eight characters. If so, four characters should be selected. This remains a finding when set to four characters, but is mitigated to a CAT 3.

Where passwords are used, confirm the characters are changed in at least eight of the positions within the password. This requirement may be verified by demonstration, configuration review, or validated test results.

[edit system login password]
:
minimum-character-changes 8;
:

If the network device and associated authentication server does not require that when a password is changed, the characters are changed in at least eight of the positions within the password, this is a finding.

Check Content Reference

M

Target Key

5477