STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must terminate shared/group account credentials when members leave the group.

DISA Rule

SV-266065r1024596_rule

Vulnerability Number

V-266065

Group Title

SRG-APP-000317-NDM-000282

Rule Version

F5BI-DM-300003

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. System.
2. Users.
3. User List.
4. Check the box next to any shared/group accounts that must not be active.
5. Click "Delete".
6. Click "Delete" again on the next page.

From the BIG-IP console, type the following command:

tmsh delete auth user <username>
tmsh save sys config

Check Contents

From the BIG-IP GUI:
1. System.
2. Users.
3. User List.

From the BIG-IP console, type the following command:

tmsh list auth user

If there are any shared accounts that must not be active, this is a finding.

Vulnerability Number

V-266065

Documentable

False

Rule Version

F5BI-DM-300003

Severity Override Guidance

From the BIG-IP GUI:
1. System.
2. Users.
3. User List.

From the BIG-IP console, type the following command:

tmsh list auth user

If there are any shared accounts that must not be active, this is a finding.

Check Content Reference

M

Target Key

5639