STIGQter STIGQter: STIG Summary: Riverbed NetIM NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The Riverbed NetIM must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.

DISA Rule

SV-275453r1147409_rule

Vulnerability Number

V-275453

Group Title

SRG-APP-000148-NDM-000346

Rule Version

RIIM-DM-000004

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Use of the default GUI account "admin" as the account of last resort is strongly recommended. It must have a DOD-compliant password and be securely stored in a safe for emergency, but not day-to-day, use. The "NetIMAdmin" default shell account cannot be changed but must be the only user shell account. It must have a DOD-compliant password.

Remove all GUI local accounts other than the default admin account.

1. In the GUI, navigate to Configure >> All Settings >> Administer >> User Management.
2. In the Local Users section, click the "X" icon in the Actions column of the user's entry.

The NetIMAdmin shell account must remain the only local login account at this level.

Check Contents

Verify only the account of last resort, "admin", exists on the device.

In the GUI, navigate to Configure >> All Settings >> Administer >> User Management.

If local user accounts exist other than the account of last resort, this is a finding.

Vulnerability Number

V-275453

Documentable

False

Rule Version

RIIM-DM-000004

Severity Override Guidance

Verify only the account of last resort, "admin", exists on the device.

In the GUI, navigate to Configure >> All Settings >> Administer >> User Management.

If local user accounts exist other than the account of last resort, this is a finding.

Check Content Reference

M

Target Key

5704