STIGQter STIGQter: STIG Summary: Riverbed NetProfiler Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Riverbed NetProfiler must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.

DISA Rule

SV-256078r960969_rule

Vulnerability Number

V-256078

Group Title

SRG-APP-000148-NDM-000346

Rule Version

RINP-DM-000027

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Use of the factory-created "admin" account as the account of last resort is strongly recommended. It must have a DOD-compliant password and be securely stored in a safe for emergency but not day-to-day use.

Go to the Configuration >> Manage Accounts >> User Accounts >> Settings page.

In the Global account settings configuration window, ensure the "Prevent user 'admin' from being locked out via a DOS attack" feature applies to only the factory-created admin account.

Check Contents

Navigate to the Configuration >> Account Management >> User Accounts page.

If accounts exist other than the "admin" account, this is a finding.

Vulnerability Number

V-256078

Documentable

False

Rule Version

RINP-DM-000027

Severity Override Guidance

Navigate to the Configuration >> Account Management >> User Accounts page.

If accounts exist other than the "admin" account, this is a finding.

Check Content Reference

M

Target Key

5514