STIGQter STIGQter: STIG Summary: Nutanix Acropolis GPOS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Jan 2026:

Nutanix OS must require users to reauthenticate for privilege escalation.

DISA Rule

SV-279598r1192561_rule

Vulnerability Number

V-279598

Group Title

SRG-OS-000373-GPOS-00156

Rule Version

NXAC-OS-000152

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove occurrences of "NOPASSWD".

1. For AOS, use the following command.

salt-call state.sls security/CVM/manualCVM

2. For Prism Central, use the following command.

salt-call state.sls security/PCVM/manualPCVM

3. For Files, use the following command.

salt-call state.sls security/AFS/manualAFS

4. The AHV hypervisor does not support local interactive user accounts. AHV has been designed and configured to run essentially headless. The only accounts allowed on AHV are the preconfigured system accounts.

Check Contents

For AHV, this requirement is Not Applicable.

Confirm Nutanix OS is configured as shown for reauthentication in the sudoers file:

$ grep -i nopasswd /etc/sudoers /etc/sudoers.d/*

If any occurrences of "NOPASSWD" are returned from the command and have not been documented with the information system security officer (ISSO) as an organizationally defined administrative group using multifactor authentication (MFA), this is a finding.

Vulnerability Number

V-279598

Documentable

False

Rule Version

NXAC-OS-000152

Severity Override Guidance

For AHV, this requirement is Not Applicable.

Confirm Nutanix OS is configured as shown for reauthentication in the sudoers file:

$ grep -i nopasswd /etc/sudoers /etc/sudoers.d/*

If any occurrences of "NOPASSWD" are returned from the command and have not been documented with the information system security officer (ISSO) as an organizationally defined administrative group using multifactor authentication (MFA), this is a finding.

Check Content Reference

M

Target Key

5730