STIGQter STIGQter: STIG Summary: Web Server Security Requirements Guide Version: 4 Release: 5 Benchmark Date: 01 Jul 2026:

The web server must, for password-based authentication, verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).

DISA Rule

SV-264348r984389_rule

Vulnerability Number

V-264348

Group Title

SRG-APP-000845

Rule Version

SRG-APP-000845-WSR-000220

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the web server to verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).

Check Contents

Verify the web server is configured to verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).

If the web server is not configured to verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a), this is a finding.

Vulnerability Number

V-264348

Documentable

False

Rule Version

SRG-APP-000845-WSR-000220

Severity Override Guidance

Verify the web server is configured to verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).

If the web server is not configured to verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a), this is a finding.

Check Content Reference

M

Target Key

2910