STIGQter STIGQter: STIG Summary: VMware NSX 4.x Manager NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Manager must enforce password complexity by requiring that at least one uppercase character be used for local accounts.

DISA Rule

SV-265317r994174_rule

Vulnerability Number

V-265317

Group Title

SRG-APP-000166-NDM-000254

Rule Version

NMGR-4X-000040

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From an NSX Manager shell, run the following command:

> set password-complexity upper-chars -1

Note: Negative numbers indicate a minimum number of characters.

Check Contents

From an NSX Manager shell, run the following command:

> get password-complexity

If the minimum uppercase characters is not 1 or more, this is a finding.

Note: If a maximum number of uppercase characters has been configured a minimum will not be shown.

Vulnerability Number

V-265317

Documentable

False

Rule Version

NMGR-4X-000040

Severity Override Guidance

From an NSX Manager shell, run the following command:

> get password-complexity

If the minimum uppercase characters is not 1 or more, this is a finding.

Note: If a maximum number of uppercase characters has been configured a minimum will not be shown.

Check Content Reference

M

Target Key

5633