STIGQter STIGQter: STIG Summary: VMware vSphere 7.0 VAMI Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 26 Jul 2023:

VAMI server binaries and libraries must be verified for their integrity.

DISA Rule

SV-256653r888481_rule

Vulnerability Number

V-256653

Group Title

SRG-APP-000131-WSR-000051

Rule Version

VCLD-70-000009

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the VAMI binaries have been modified from the default state when deployed as part of the vCenter Server Appliance (VCSA), the system must be wiped and redeployed or restored from backup.

VMware does not recommend or support recovering from such a state by reinstalling RPMs or similar efforts.

Check Contents

At the command prompt, run the following command:

# rpm -qa|grep lighttpd|xargs rpm -V|grep -v -E "lighttpd.conf|vami-lighttp.service"

If the command returns any output, this is a finding.

Vulnerability Number

V-256653

Documentable

False

Rule Version

VCLD-70-000009

Severity Override Guidance

At the command prompt, run the following command:

# rpm -qa|grep lighttpd|xargs rpm -V|grep -v -E "lighttpd.conf|vami-lighttp.service"

If the command returns any output, this is a finding.

Check Content Reference

M

Target Key

5523