STIGQter STIGQter: STIG Summary: Cisco ACI NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI must implement replay-resistant authentication mechanisms for network access to privileged accounts.

DISA Rule

SV-271936r1113837_rule

Vulnerability Number

V-271936

Group Title

SRG-APP-000156-NDM-000250

Rule Version

CACI-ND-000021

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the default fabric TLS Protocol:
1. On the menu bar, choose Fabric >> Fabric Policies.
2. In the Navigation pane, choose Policies >> Pod >> Management Access >> default.
3. In the Work pane, find the HTTPS section.
4. For SSL Protocols, check the boxes for TLS 1.2 or higher. Uncheck or leave unchecked for any other SSL or TLS version.

Check Contents

Verify the default fabric TLS Protocol:
1. On the menu bar, choose Fabric >> Fabric Policies.
2. In the Navigation pane, select Policies >> Pod >> Management Access >> default.
3. In the Work pane, find the HTTPS section.
4. For SSL Protocols, verify the box for TLS 1.2 or higher is checked. Verify other SSL or TLS versions are not checked.

If the Cisco ACI fabric does not implement TLS 1.2 or higher for authentication for network access to privileged accounts, this is a finding.

Vulnerability Number

V-271936

Documentable

False

Rule Version

CACI-ND-000021

Severity Override Guidance

Verify the default fabric TLS Protocol:
1. On the menu bar, choose Fabric >> Fabric Policies.
2. In the Navigation pane, select Policies >> Pod >> Management Access >> default.
3. In the Work pane, find the HTTPS section.
4. For SSL Protocols, verify the box for TLS 1.2 or higher is checked. Verify other SSL or TLS versions are not checked.

If the Cisco ACI fabric does not implement TLS 1.2 or higher for authentication for network access to privileged accounts, this is a finding.

Check Content Reference

M

Target Key

5682