STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Network Device Management Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia router must protect audit information from unauthorized modification.

DISA Rule

SV-283766r1203597_rule

Vulnerability Number

V-283766

Group Title

SRG-APP-000119-NDM-000236

Rule Version

NOKI-ND-000260

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Nokia router to protect audit information from unauthorized modification by configuring authentication servers and applying correct authorization privileges for each user.

Multiple RADIUS servers can be configured per the configuration below:

- configure system security radius
- accounting
- authorization

- server <radius server ip address>

For local accounts, assign the correct user profile to each user:

- configure system security user <user name> console member <profile name>

Users can also be restricted to the user's home directory. If the home directory for the user is not configured, the user does not have access to any directory:

- configure system security user <user name>
- restricted-to-home

If the user requires a directory, it can be configured using the command below:

- home-directory <directory >

Check Contents

Determine if the Nokia router protects audit information from any type of unauthorized modification with such methods as ensuring log files receive the proper file system permissions, limiting log data locations, and leveraging user permissions and roles to identify the user accessing the data and the corresponding user rights.

Verify the authentication server is configured using the command below:

- show system security authentication

Verify authentication servers are configured with correct user privileges to restrict access to the router file system.

Verify each local user has the correct "profile" assigned, the user is "restricted to home", and the "home directory" is defined:

- show system security user detail

If the Nokia router is not configured with external authentication servers, this is a finding.

Vulnerability Number

V-283766

Documentable

False

Rule Version

NOKI-ND-000260

Severity Override Guidance

Determine if the Nokia router protects audit information from any type of unauthorized modification with such methods as ensuring log files receive the proper file system permissions, limiting log data locations, and leveraging user permissions and roles to identify the user accessing the data and the corresponding user rights.

Verify the authentication server is configured using the command below:

- show system security authentication

Verify authentication servers are configured with correct user privileges to restrict access to the router file system.

Verify each local user has the correct "profile" assigned, the user is "restricted to home", and the "home directory" is defined:

- show system security user detail

If the Nokia router is not configured with external authentication servers, this is a finding.

Check Content Reference

M

Target Key

5744