STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must enforce password complexity by requiring that at least one uppercase character be used.

DISA Rule

SV-266088r1024894_rule

Vulnerability Number

V-266088

Group Title

SRG-APP-000166-NDM-000254

Rule Version

F5BI-DM-300050

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Under "Password Policy" set "Secure Password Enforcement" to "Enabled".
5. Under "Required Characters" set "Uppercase" to at least 1.
6. Click "Update".

From the BIG-IP console, type the following command(s):

tmsh modify auth password-policy required-uppercase 1
tmsh save sys config

Check Contents

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Verify that "Secure Password Enforcement" is set to "Enabled".
5. Verify under "Required Characters" that "Uppercase" is set to at least 1.

From the BIG-IP console, type the following command(s):

tmsh list auth password-policy required-uppercase

Note: Verify the value is set to at least 1.

If the BIG-IP appliance is not configured to enforce password complexity by requiring that at least one uppercase character be used, this is a finding.

Vulnerability Number

V-266088

Documentable

False

Rule Version

F5BI-DM-300050

Severity Override Guidance

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Verify that "Secure Password Enforcement" is set to "Enabled".
5. Verify under "Required Characters" that "Uppercase" is set to at least 1.

From the BIG-IP console, type the following command(s):

tmsh list auth password-policy required-uppercase

Note: Verify the value is set to at least 1.

If the BIG-IP appliance is not configured to enforce password complexity by requiring that at least one uppercase character be used, this is a finding.

Check Content Reference

M

Target Key

5639