STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must enforce password complexity by requiring that at least one numeric character be used.

DISA Rule

SV-266090r1024623_rule

Vulnerability Number

V-266090

Group Title

SRG-APP-000168-NDM-000256

Rule Version

F5BI-DM-300052

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Under "Password Policy" set "Secure Password Enforcement" to "Enabled".
5. Under "Required Characters" set "Numeric" to at least 1.
6. Click "Update".

From the BIG-IP console, type the following command:

tmsh modify auth password-policy required-numeric 1
tmsh save sys config

Check Contents

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Verify that "Secure Password Enforcement" is set to "Enabled".
5. Verify under "Required Characters" that "Numeric" is set to at least 1.

From the BIG-IP console, type the following command:

tmsh list auth password-policy required-numeric

Note: Verify the value is set to at least 1.

If the BIG-IP appliance is not configured to enforce password complexity by requiring that at least one numeric character be used, this is a finding.

Vulnerability Number

V-266090

Documentable

False

Rule Version

F5BI-DM-300052

Severity Override Guidance

From the BIG-IP GUI:
1. System.
2. Users.
3. Authentication.
4. Verify that "Secure Password Enforcement" is set to "Enabled".
5. Verify under "Required Characters" that "Numeric" is set to at least 1.

From the BIG-IP console, type the following command:

tmsh list auth password-policy required-numeric

Note: Verify the value is set to at least 1.

If the BIG-IP appliance is not configured to enforce password complexity by requiring that at least one numeric character be used, this is a finding.

Check Content Reference

M

Target Key

5639