STIGQter STIGQter: STIG Summary: VMware ESX 3 Server Version: 1 Release: 2 Benchmark Date: 22 Jul 2016: The system must require at least four characters be changed between the old and new passwords during a password change.

DISA Rule

SV-25953r1_rule

Vulnerability Number

V-22306

Group Title

GEN000750

Rule Version

GEN000750

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Consult vendor documentation for the configuration setting that controls the minimum number of changed characters required during a password change. Change the setting to 4.

Check Contents

Consult vendor documentation for the configuration setting that controls the minimum number of changed characters required during a password change. If the configured number is less than 4, this is a finding.

Vulnerability Number

V-22306

Documentable

False

Rule Version

GEN000750

Severity Override Guidance

Consult vendor documentation for the configuration setting that controls the minimum number of changed characters required during a password change. If the configured number is less than 4, this is a finding.

Check Content Reference

M

Responsibility

System Administrator

Target Key

1386

Comments