STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 vCenter Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 31 Oct 2023:

The vCenter Server must be isolated from the public internet but must still allow for patch notification and delivery.

DISA Rule

SV-258944r934490_rule

Vulnerability Number

V-258944

Group Title

SRG-APP-000516

Rule Version

VCSA-80-000277

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Option 1:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Click the "Change Download Source" button.

Select the "Download patches from a UMDS shared repository" radio button and supply a valid UMDS repository.

Click "Save".

Option 2:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Click the "Change Download Source" button.

Select the "Download patches directly from the internet" radio button.

Click "Save".

Navigate to the vCenter Server Management interface at https://<vcenter dns>:5480 >> Networking >> Proxy Settings.

Click "Edit".

Slide "HTTPS" to "Enabled".

Supply the appropriate proxy server configuration.

Click "Save".

Option 3:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Downloads.

Click "Edit" and uncheck "Download patches".

Under "Patch Setup" select each download source and click Disable.

Check Contents

Check the following conditions:

1. Lifecycle Manager must be configured to use the UMDS.

OR

2. Lifecycle Manager must be configured to use a proxy server for access to VMware patch repositories.

OR

3. Lifecycle Manager must disable internet patch repositories and any patches must be manually validated and imported as needed.

Option 1:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Click the "Change Download Source" button.

Verify the "Download patches from a UMDS shared repository" radio button is selected and that a valid UMDS repository is supplied.

Click "Cancel".

If this is not set, this is a finding.

Option 2:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Click the "Change Download Source" button.

Verify the "Download patches directly from the internet" radio button is selected.

Click "Cancel".

Navigate to the vCenter Server Management interface at https://<vcenter dns>:5480 >> Networking >> Proxy Settings.

Verify that "HTTPS" is "Enabled".

Click the "HTTPS" row.

Verify the proxy server configuration is accurate.

If this is not set, this is a finding.

Option 3:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Downloads.

Verify the "Automatic downloads" option is disabled.

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Verify any download sources are disabled.

If this is not set, this is a finding.

Vulnerability Number

V-258944

Documentable

False

Rule Version

VCSA-80-000277

Severity Override Guidance

Check the following conditions:

1. Lifecycle Manager must be configured to use the UMDS.

OR

2. Lifecycle Manager must be configured to use a proxy server for access to VMware patch repositories.

OR

3. Lifecycle Manager must disable internet patch repositories and any patches must be manually validated and imported as needed.

Option 1:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Click the "Change Download Source" button.

Verify the "Download patches from a UMDS shared repository" radio button is selected and that a valid UMDS repository is supplied.

Click "Cancel".

If this is not set, this is a finding.

Option 2:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Click the "Change Download Source" button.

Verify the "Download patches directly from the internet" radio button is selected.

Click "Cancel".

Navigate to the vCenter Server Management interface at https://<vcenter dns>:5480 >> Networking >> Proxy Settings.

Verify that "HTTPS" is "Enabled".

Click the "HTTPS" row.

Verify the proxy server configuration is accurate.

If this is not set, this is a finding.

Option 3:

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Downloads.

Verify the "Automatic downloads" option is disabled.

From the vSphere Client, go to Lifecycle Manager >> Settings >> Patch Setup.

Verify any download sources are disabled.

If this is not set, this is a finding.

Check Content Reference

M

Target Key

5573