STIGQter STIGQter: STIG Summary: VMware NSX 4.x Manager NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The NSX Manager must enforce password complexity by requiring that at least one numeric character be used for local accounts.

DISA Rule

SV-265319r994180_rule

Vulnerability Number

V-265319

Group Title

SRG-APP-000168-NDM-000256

Rule Version

NMGR-4X-000042

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From an NSX Manager shell, run the following command:

> set password-complexity digits -1

Note: Negative numbers indicate a minimum number of characters.

Check Contents

From an NSX Manager shell, run the following command:

> get password-complexity

If the minimum numeric characters is not 1 or more, this is a finding.

Note: If a maximum number of numeric characters has been configured, a minimum will not be shown.

Vulnerability Number

V-265319

Documentable

False

Rule Version

NMGR-4X-000042

Severity Override Guidance

From an NSX Manager shell, run the following command:

> get password-complexity

If the minimum numeric characters is not 1 or more, this is a finding.

Note: If a maximum number of numeric characters has been configured, a minimum will not be shown.

Check Content Reference

M

Target Key

5633