STIGQter STIGQter: STIG Summary: Ivanti Connect Secure NDM Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Oct 2025:

The ICS must be configured to run an operating system release that is currently supported by Ivanti.

DISA Rule

SV-258613r961863_rule

Vulnerability Number

V-258613

Group Title

SRG-APP-000516-NDM-000351

Rule Version

IVCS-NM-000410

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Navigate to the ICS support site https://my.pulsesecure.net/.
1. Login using the valid support login.
2. Click the link for "Software Licensing and Download".
3. Click either virtual or physical appliance.
4. Click "Software Download".
5. Under Product Lines, click "Pulse Connect Secure" and again, "Pulse Connect Secure".
6. Click "Current and Supported Releases".
7. Click "Download" on the latest ICS images.

Using the ICS Web UI navigate to Maintenance >> System >> Upgrade/Downgrade.
1. Ensure the ICS is upgraded in accordance with the site's change management and change control policies, as this will cause a platform outage.
2. Under "Install Service Package" click "Browse" and select the recently downloaded images.
3. Click "Install".
4. Follow all prompts for the upgrading the new images.

Check Contents

Navigate to the ICS support site https://my.pulsesecure.net/.
1. Login using the valid support login.
2. Click the link for "Software Licensing and Download".
3. Click "License and System Download".
4. Click "Software Download".
5. Under "Product Lines", click "Pulse Connect Secure" and again, "Pulse Connect Secure".
6. Click the "End of Support" tab.
7. Now using the ICS Web UI, navigate to Maintenance >> System >> Platform.

If the version running under Current Version is on the list of End of Support images on the Ivanti support site, this is a finding.

Vulnerability Number

V-258613

Documentable

False

Rule Version

IVCS-NM-000410

Severity Override Guidance

Navigate to the ICS support site https://my.pulsesecure.net/.
1. Login using the valid support login.
2. Click the link for "Software Licensing and Download".
3. Click "License and System Download".
4. Click "Software Download".
5. Under "Product Lines", click "Pulse Connect Secure" and again, "Pulse Connect Secure".
6. Click the "End of Support" tab.
7. Now using the ICS Web UI, navigate to Maintenance >> System >> Platform.

If the version running under Current Version is on the list of End of Support images on the Ivanti support site, this is a finding.

Check Content Reference

M

Target Key

5558