STIGQter STIGQter: STIG Summary: Ivanti Connect Secure NDM Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Oct 2025:

The ICS must be configured to transmit only encrypted representations of passwords.

DISA Rule

SV-258615r961029_rule

Vulnerability Number

V-258615

Group Title

SRG-APP-000172-NDM-000259

Rule Version

IVCS-NM-000450

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

In the ICS Web UI, navigate to System >> Configuration >> Inbound SSL Options.
1. Under "Allowed SSL and TLS Version", check the box for "Accept only TLS 1.2 (maximize security)".
2. Click "Save Changes".
3. Click "Proceed" for acceptance of Cipher Change.

Navigate to System >> Configuration >> Outbound SSL Options.
1. Under "Allowed SSL and TLS Version", check the box for "Accept only TLS 1.2 (maximize security)".
2. Click "Save Changes".
3. Click "Proceed" for acceptance of Cipher Change.

Check Contents

In the ICS Web UI, navigate to System >> Configuration >> Inbound SSL Options.

Under "Allowed SSL and TLS Version", if "Accept only TLS 1.2 (maximize security)" is checked.

Navigate to System >> Configuration >> Outbound SSL Options.

Under "Allowed SSL and TLS Version", if "Accept only TLS 1.2 (maximize security)" is checked.

If the ICS does not transmit only encrypted representations of passwords, this is a finding.

Vulnerability Number

V-258615

Documentable

False

Rule Version

IVCS-NM-000450

Severity Override Guidance

In the ICS Web UI, navigate to System >> Configuration >> Inbound SSL Options.

Under "Allowed SSL and TLS Version", if "Accept only TLS 1.2 (maximize security)" is checked.

Navigate to System >> Configuration >> Outbound SSL Options.

Under "Allowed SSL and TLS Version", if "Accept only TLS 1.2 (maximize security)" is checked.

If the ICS does not transmit only encrypted representations of passwords, this is a finding.

Check Content Reference

M

Target Key

5558