STIGQter STIGQter: STIG Summary: VMware NSX 4.x Manager NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Manager must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.

DISA Rule

SV-265313r1051115_rule

Vulnerability Number

V-265313

Group Title

SRG-APP-000148-NDM-000346

Rule Version

NMGR-4X-000035

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the NSX Manager web interface, go to the System >> Settings >> User Management >> Local Users.

Select the menu drop down next to any local user on the list except for the "admin" account. Click modify and click "Deactivate User".

Check Contents

From the NSX Manager web interface, go to the System >> Settings >> User Management >> Local Users and view the status column.

If any local account other than the account of last resort are active, this is a finding.

Vulnerability Number

V-265313

Documentable

False

Rule Version

NMGR-4X-000035

Severity Override Guidance

From the NSX Manager web interface, go to the System >> Settings >> User Management >> Local Users and view the status column.

If any local account other than the account of last resort are active, this is a finding.

Check Content Reference

M

Target Key

5633