STIGQter STIGQter: STIG Summary: Dell OS10 Switch NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 Dec 2024:

The Dell OS10 Switch must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.

DISA Rule

SV-269778r1051719_rule

Vulnerability Number

V-269778

Group Title

SRG-APP-000148-NDM-000346

Rule Version

OS10-NDM-000360

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the OS10 Switch to only allow one local account for use as the account of last resort.

Disable the linuxadmin system user:

OS10(config)# system-user linuxadmin disable

%Warning : Operation is not recommended in absence of console access.
Do you want to proceed ? [yes/no(default)]:yes
OS10(config)#

Delete any extra local users with the following command:

OS10(config)# no username admin

Note: The account of last resort must be added before the default admin account can be deleted.

Check Contents

Review the network device configuration to determine if an account of last resort is configured. Verify default admin and other vendor-provided accounts are disabled, removed, or renamed where possible. Verify the username and password for the account of last resort is contained within a sealed envelope and kept in a safe.

Step 1: Verify the Dell OS10 Switch is configured with only a single local user account. If one local account does not exist for use as the account of last resort, this is a finding.

Verify the role is sysadmin.

OS10# show running-configuration users
username alradmin password **** role sysadmin priv-lvl 15
OS10#

Step 2: Verify the linuxadmin system user has been disabled:

OS10# show running-configuration | grep system-user
system-user linuxadmin disable
system-user linuxadmin password ****
OS10#

If one local account does not exist for use as the account of last resort or the linuxadmin system-user has not been disabled, this is a finding.

Vulnerability Number

V-269778

Documentable

False

Rule Version

OS10-NDM-000360

Severity Override Guidance

Review the network device configuration to determine if an account of last resort is configured. Verify default admin and other vendor-provided accounts are disabled, removed, or renamed where possible. Verify the username and password for the account of last resort is contained within a sealed envelope and kept in a safe.

Step 1: Verify the Dell OS10 Switch is configured with only a single local user account. If one local account does not exist for use as the account of last resort, this is a finding.

Verify the role is sysadmin.

OS10# show running-configuration users
username alradmin password **** role sysadmin priv-lvl 15
OS10#

Step 2: Verify the linuxadmin system user has been disabled:

OS10# show running-configuration | grep system-user
system-user linuxadmin disable
system-user linuxadmin password ****
OS10#

If one local account does not exist for use as the account of last resort or the linuxadmin system-user has not been disabled, this is a finding.

Check Content Reference

M

Target Key

5666