STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 ESXi Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The ESXi host must enable Secure Boot.

DISA Rule

SV-258741r1003563_rule

Vulnerability Number

V-258741

Group Title

SRG-OS-000278-VMM-001000

Rule Version

ESXI-80-000094

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From an ESXi shell, run the following command:

# /usr/lib/vmware/secureboot/bin/secureBoot.py -c

If the output indicates that Secure Boot cannot be enabled, correct the discrepancies and try again.

Once all discrepancies are resolved, the server ESXi is installed on can be updated to enable Secure Boot in the firmware.

To enable Secure Boot in the server's firmware, follow the instructions for the specific manufacturer.

Check Contents

From an ESXi shell, run the following command:

# /usr/lib/vmware/secureboot/bin/secureBoot.py -s

or

From a PowerCLI command prompt while connected to the ESXi host, run the following command:

((Get-VMHost).ExtensionData.Capability).UefiSecureBoot

If Secure Boot is not enabled, this is a finding.

Vulnerability Number

V-258741

Documentable

False

Rule Version

ESXI-80-000094

Severity Override Guidance

From an ESXi shell, run the following command:

# /usr/lib/vmware/secureboot/bin/secureBoot.py -s

or

From a PowerCLI command prompt while connected to the ESXi host, run the following command:

((Get-VMHost).ExtensionData.Capability).UefiSecureBoot

If Secure Boot is not enabled, this is a finding.

Check Content Reference

M

Target Key

5562