STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must be running an operating system release that is currently supported by the vendor.

DISA Rule

SV-266080r1024886_rule

Vulnerability Number

V-266080

Group Title

SRG-APP-000516-NDM-000351

Rule Version

F5BI-DM-300041

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

If the release is not a supported version, then update the version.

From the BIG-IP GUI:
1. Import .iso.
a. System.
b. Software Management.
c. Image List.
d. Import .iso of supported BIG-IP operating system.
e. Import the corresponding .iso.sig file.
f. Install.
2. Switch boot location to new install.
a. System.
b. Software Management.
c. Boot Locations.
d. Select new install location.
e. Optionally change "Install Configuration" to "Yes".
f. Activate.

Check Contents

From the BIG-IP GUI:
1. System.
2. Configuration.
3. Device.
4. General.
5. Verify "Version" is currently supported according to the vendor support site.

From the BIG-IP console, type the following command(s):

tmsh list cm device version

Note: Verify the version is currently supported on the vendor's website.

If the BIG-IP appliance is not running an operating system release that is currently supported by the vendor, this is a finding.

Vulnerability Number

V-266080

Documentable

False

Rule Version

F5BI-DM-300041

Severity Override Guidance

From the BIG-IP GUI:
1. System.
2. Configuration.
3. Device.
4. General.
5. Verify "Version" is currently supported according to the vendor support site.

From the BIG-IP console, type the following command(s):

tmsh list cm device version

Note: Verify the version is currently supported on the vendor's website.

If the BIG-IP appliance is not running an operating system release that is currently supported by the vendor, this is a finding.

Check Content Reference

M

Target Key

5639