STIGQter STIGQter: STIG Summary: Riverbed NetIM NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The Riverbed NetIM must be configured to require immediate selection of a new password upon account recovery for password-based authentication.

DISA Rule

SV-275466r1147448_rule

Vulnerability Number

V-275466

Group Title

SRG-APP-000080-NDM-000220

Rule Version

RIIM-DM-000020

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure Password Rules to expire temporary passwords.

1. From the GUI, navigate to Configuration >> Configure >> All Settings >> Administer.
2. On the User Management screen, select "Password Rules".
3. Check "Maximum age of temporary password in hours".
4. Enter an organization-defined number in the option box and click "Submit".

Local users must not be created; however, setting these requirements is a best practice.

Check Contents

Verify Password Rules is configured to expire temporary passwords.

1. From the GUI, navigate to Configuration >> Configure >> All Settings >> Administer.
2. On the User Management screen, select "Password Rules".
3. View the Maximum age of temporary password in hours.

If the Maximum age of temporary password in hours is not set, this is a finding.

Vulnerability Number

V-275466

Documentable

False

Rule Version

RIIM-DM-000020

Severity Override Guidance

Verify Password Rules is configured to expire temporary passwords.

1. From the GUI, navigate to Configuration >> Configure >> All Settings >> Administer.
2. On the User Management screen, select "Password Rules".
3. View the Maximum age of temporary password in hours.

If the Maximum age of temporary password in hours is not set, this is a finding.

Check Content Reference

M

Target Key

5704