STIGQter STIGQter: STIG Summary: HPE Aruba Networking AOS NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 22 Oct 2024:

AOS must be configured to assign appropriate user roles or access levels to authenticated users.

DISA Rule

SV-266909r1039960_rule

Vulnerability Number

V-266909

Group Title

SRG-APP-000033-NDM-000212

Rule Version

ARBA-ND-000212

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure AOS using the web interface:

Navigate to Configuration >> System >> Admin tab and expand the "Admin Authentication Options".

Select root for the Default role.

Check the "Enable" checkbox.

Select the enterprise Server group that is configured for admin authorization.

Click Submit >> Pending Changes >> Deploy changes.

Check Contents

Verify the AOS configuration using the web interface:

Navigate to Configuration >> System >> Admin tab and expand the "Admin Authentication Options".

If root is not the Default role, "Enable" is not checked, or the Server group is not configured to the enterprise server group for admin authorization, this is a finding.

Vulnerability Number

V-266909

Documentable

False

Rule Version

ARBA-ND-000212

Severity Override Guidance

Verify the AOS configuration using the web interface:

Navigate to Configuration >> System >> Admin tab and expand the "Admin Authentication Options".

If root is not the Default role, "Enable" is not checked, or the Server group is not configured to the enterprise server group for admin authorization, this is a finding.

Check Content Reference

M

Target Key

5648