STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.

DISA Rule

SV-266066r1051115_rule

Vulnerability Number

V-266066

Group Title

SRG-APP-000148-NDM-000346

Rule Version

F5BI-DM-300009

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. System.
2. Users.
3. User List.
4. Delete any local users that are not the account of last resort.

From the BIG-IP console, type the following commands:

tmsh delete auth user <username>
tmsh save sys config

Check Contents

From the BIG-IP GUI:
1. System.
2. Users.
3. User List.
4. Verify there is only one account of last resort listed.

From the BIG-IP console, type the following command:

tmsh list auth user

If there is more than one account of last resort listed, this is a finding.

Vulnerability Number

V-266066

Documentable

False

Rule Version

F5BI-DM-300009

Severity Override Guidance

From the BIG-IP GUI:
1. System.
2. Users.
3. User List.
4. Verify there is only one account of last resort listed.

From the BIG-IP console, type the following command:

tmsh list auth user

If there is more than one account of last resort listed, this is a finding.

Check Content Reference

M

Target Key

5639