STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must require that when a password is changed, the characters are changed in at least eight of the positions within the password.

DISA Rule

SV-266092r1043189_rule

Vulnerability Number

V-266092

Group Title

SRG-APP-000170-NDM-000329

Rule Version

F5BI-DM-300054

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If this setting has been changed from the default value of 8, reset the value.

From the BIG-IP console, type the following command:

tmsh modify sys db password.difok value 8
tmsh save sys config

Check Contents

From the BIG-IP console, type the following command:

tmsh list sys db password.difok

Note: Verify the value is set to at least 8.

If the BIG-IP appliance is not configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password, this is a finding.

Vulnerability Number

V-266092

Documentable

False

Rule Version

F5BI-DM-300054

Severity Override Guidance

From the BIG-IP console, type the following command:

tmsh list sys db password.difok

Note: Verify the value is set to at least 8.

If the BIG-IP appliance is not configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password, this is a finding.

Check Content Reference

M

Target Key

5639