STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must be configured to assign appropriate user roles or access levels to authenticated users.

DISA Rule

SV-266067r1024598_rule

Vulnerability Number

V-266067

Group Title

SRG-APP-000033-NDM-000212

Rule Version

F5BI-DM-300010

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Remote Roles (e.g., RADIUS, LDAP groups)
From the BIG-IP GUI:
1. System.
2. Users.
3. Remote Role Groups.
4. Select the Group Name.
5. Modify the Properties of the group to the appropriate access level.
6. Update.

Local Users
1. System.
2. Users.
3. User List.
4. Select the user.
5. Modify "Partition Access" to the appropriate access level.
6. Update.

Check Contents

From the BIG-IP GUI:
1. System.
2. Users.
3. Remote Role Groups.
4. Verify configured groups are assigned the appropriate role.

From the BIG-IP console, type the following command:

tmsh list auth remote-role

Note: Verify configured groups are assigned the appropriate role.

If the BIG-IP appliance is not configured to assign appropriate user roles or access levels to authenticated users, this is a finding.

Vulnerability Number

V-266067

Documentable

False

Rule Version

F5BI-DM-300010

Severity Override Guidance

From the BIG-IP GUI:
1. System.
2. Users.
3. Remote Role Groups.
4. Verify configured groups are assigned the appropriate role.

From the BIG-IP console, type the following command:

tmsh list auth remote-role

Note: Verify configured groups are assigned the appropriate role.

If the BIG-IP appliance is not configured to assign appropriate user roles or access levels to authenticated users, this is a finding.

Check Content Reference

M

Target Key

5639