STIGQter STIGQter: STIG Summary: Dell OS10 Switch NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 Dec 2024:

The Dell OS10 Switch must enforce access restrictions associated with changes to the system components.

DISA Rule

SV-269801r1051788_rule

Vulnerability Number

V-269801

Group Title

SRG-APP-000516-NDM-000335

Rule Version

OS10-NDM-000920

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure any unauthorized users to have the netoperator role that cannot make any changes:

OS10(config)# username <name> password ********** role netoperator

Check Contents

Check the OS10 Switch to determine if only authorized administrators have permissions for changes, deletions, and updates on the network device. Inspect the maintenance log to verify changes are being made only by the authorized administrators.

Changes, deletions, and updates in Dell OS10 can only be done by users with sysadmin, secadmin, or netadmin role. Verify if there are any unauthorized users assigned to the any of these roles:

OS10# show running-configuration users

If any unauthorized users are assigned to the sysadmin, secadmin, or netadmin role, this is a finding.

Vulnerability Number

V-269801

Documentable

False

Rule Version

OS10-NDM-000920

Severity Override Guidance

Check the OS10 Switch to determine if only authorized administrators have permissions for changes, deletions, and updates on the network device. Inspect the maintenance log to verify changes are being made only by the authorized administrators.

Changes, deletions, and updates in Dell OS10 can only be done by users with sysadmin, secadmin, or netadmin role. Verify if there are any unauthorized users assigned to the any of these roles:

OS10# show running-configuration users

If any unauthorized users are assigned to the sysadmin, secadmin, or netadmin role, this is a finding.

Check Content Reference

M

Target Key

5666