STIGQter STIGQter: STIG Summary: VMware vSphere 7.0 vCenter Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 24 Jan 2024:

The vCenter Server must be isolated from the public internet but must still allow for patch notification and delivery.

DISA Rule

SV-256357r885682_rule

Vulnerability Number

V-256357

Group Title

SRG-APP-000516

Rule Version

VCSA-70-000277

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Option 1:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Click the "Change Download Source" button.

Select the "Download patches from a UMDS shared repository" radio button and supply a valid UMDS repository.

Click "Save".

Option 2:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Click the "Change Download Source" button.

Select the "Download patches directly from the internet" radio button.

Click "Save".

Navigate to the vCenter Server Management interface at https://<vcenter dns>:5480 >> Networking >> Proxy Settings.

Click "Edit".

Slide "HTTPS" to "Enabled".

Supply the appropriate proxy server configuration.

Click "Save".

Option 3:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Downloads.

Click "Edit" and uncheck "Download patches".

Under "Patch Setup", select each download source and click "Disable".

Check Contents

Check the following conditions:

1. Lifecycle Manager must be configured to use the UMDS.

OR

2. Lifecycle Manager must be configured to use a proxy server for access to VMware patch repositories.

OR

3. Lifecycle Manager must disable internet patch repositories and any patches must be manually validated and imported as needed.

Option 1:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Click the "Change Download Source" button.

Verify the "Download patches from a UMDS shared repository" radio button is selected and a valid UMDS repository is supplied.

Click "Cancel".

If this is not set, this is a finding.

Option 2:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Click the "Change Download Source" button.

Verify the "Download patches directly from the internet" radio button is selected.

Click "Cancel".

Navigate to the vCenter Server Management interface at https://<vcenter dns>:5480 >> Networking >> Proxy Settings.

Verify "HTTPS" is "Enabled".

Click the "HTTPS" row.

Verify the proxy server configuration is accurate.

If this is not set, this is a finding.

Option 3:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Downloads.

Verify the "Automatic downloads" option is disabled.

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Verify any download sources are disabled.

If this is not set, this is a finding.

Vulnerability Number

V-256357

Documentable

False

Rule Version

VCSA-70-000277

Severity Override Guidance

Check the following conditions:

1. Lifecycle Manager must be configured to use the UMDS.

OR

2. Lifecycle Manager must be configured to use a proxy server for access to VMware patch repositories.

OR

3. Lifecycle Manager must disable internet patch repositories and any patches must be manually validated and imported as needed.

Option 1:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Click the "Change Download Source" button.

Verify the "Download patches from a UMDS shared repository" radio button is selected and a valid UMDS repository is supplied.

Click "Cancel".

If this is not set, this is a finding.

Option 2:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Click the "Change Download Source" button.

Verify the "Download patches directly from the internet" radio button is selected.

Click "Cancel".

Navigate to the vCenter Server Management interface at https://<vcenter dns>:5480 >> Networking >> Proxy Settings.

Verify "HTTPS" is "Enabled".

Click the "HTTPS" row.

Verify the proxy server configuration is accurate.

If this is not set, this is a finding.

Option 3:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Downloads.

Verify the "Automatic downloads" option is disabled.

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Verify any download sources are disabled.

If this is not set, this is a finding.

Check Content Reference

M

Target Key

5517