STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 vCenter Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The vCenter Server must disable Secure Shell (SSH) access.

DISA Rule

SV-258968r1111830_rule

Vulnerability Number

V-258968

Group Title

SRG-APP-000516

Rule Version

VCSA-80-000303

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Open the Virtual Appliance Management Interface (VAMI) by navigating to https://<vCenter server>:5480.

Log in with local operating system administrative credentials or with a Single Sign-On (SSO) account that is a member of the "SystemConfiguration.BashShellAdministrator" group.

Select "Access" on the left navigation pane.

Click "Edit" then disable "Activate SSH Login" and click "OK".

Check Contents

Open the Virtual Appliance Management Interface (VAMI) by navigating to https://<vCenter server>:5480.

Log in with local operating system administrative credentials or with a Single Sign-On (SSO) account that is a member of the "SystemConfiguration.BashShellAdministrator" group.

Select "Access" on the left navigation pane.

If "SSH Login" is not "Deactivated", this is a finding.

Vulnerability Number

V-258968

Documentable

False

Rule Version

VCSA-80-000303

Severity Override Guidance

Open the Virtual Appliance Management Interface (VAMI) by navigating to https://<vCenter server>:5480.

Log in with local operating system administrative credentials or with a Single Sign-On (SSO) account that is a member of the "SystemConfiguration.BashShellAdministrator" group.

Select "Access" on the left navigation pane.

If "SSH Login" is not "Deactivated", this is a finding.

Check Content Reference

M

Target Key

5573