STIGQter STIGQter: STIG Summary: HPE Alletra Storage ArcusOS Network Device Management Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Feb 2026:

The HPE Alletra Storage ArcusOS device must be configured with only one local interactive account to be used as the account of last resort in the event the authentication server is unavailable.

DISA Rule

SV-283378r1194828_rule

Vulnerability Number

V-283378

Group Title

SRG-APP-000148-NDM-000346

Rule Version

ASMP-ND-000340

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove all interactive accounts except one account with the "super" role for last resort login with, the following command:

cli% removeuser <username>

Note: You must keep at least one account with the "super" role and it can be any organizationally defined account name.

Check Contents

Verify only one local interactive account is configured:

cli% showuser

The output will look similar to the example below:

Username Domain Role Default
adminsvc all super N
hpesupport all service N
telemetry all service N

Note: The service role accounts are not interactive and cannot be used for logins.

If more than one local interactive account to be used as the account of last resort exists, this is a finding.

Vulnerability Number

V-283378

Documentable

False

Rule Version

ASMP-ND-000340

Severity Override Guidance

Verify only one local interactive account is configured:

cli% showuser

The output will look similar to the example below:

Username Domain Role Default
adminsvc all super N
hpesupport all service N
telemetry all service N

Note: The service role accounts are not interactive and cannot be used for logins.

If more than one local interactive account to be used as the account of last resort exists, this is a finding.

Check Content Reference

M

Target Key

5742