STIGQter STIGQter: STIG Summary: VMware vSphere 7.0 ESXi Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 02 Apr 2025:

The ESXi host must verify the DCUI.Access list.

DISA Rule

SV-256376r959010_rule

Vulnerability Number

V-256376

Group Title

SRG-OS-000480-VMM-002000

Rule Version

ESXI-70-000002

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> System >> Advanced System Settings.

Click "Edit". Select the "DCUI.Access" value and configure it to "root".

or

From a PowerCLI command prompt while connected to the ESXi host, run the following command:

Get-VMHost | Get-AdvancedSetting -Name DCUI.Access | Set-AdvancedSetting -Value "root"

Check Contents

For environments that do not use vCenter server to manage ESXi, this is not applicable.

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> System >> Advanced System Settings.

Select the "DCUI.Access" value and verify only the root user is listed.

or

From a PowerCLI command prompt while connected to the ESXi host, run the following command:

Get-VMHost | Get-AdvancedSetting -Name DCUI.Access and verify it is set to root.

If the "DCUI.Access" is not restricted to "root", this is a finding.

Note: This list is only for local user accounts and should only contain the root user.

Vulnerability Number

V-256376

Documentable

False

Rule Version

ESXI-70-000002

Severity Override Guidance

For environments that do not use vCenter server to manage ESXi, this is not applicable.

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> System >> Advanced System Settings.

Select the "DCUI.Access" value and verify only the root user is listed.

or

From a PowerCLI command prompt while connected to the ESXi host, run the following command:

Get-VMHost | Get-AdvancedSetting -Name DCUI.Access and verify it is set to root.

If the "DCUI.Access" is not restricted to "root", this is a finding.

Note: This list is only for local user accounts and should only contain the root user.

Check Content Reference

M

Target Key

5518