STIGQter STIGQter: STIG Summary: AvePoint Fly Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

Fly Server must require the change of at least eight of the total number of characters when passwords are changed.

DISA Rule

SV-283934r1206156_rule

Vulnerability Number

V-283934

Group Title

SRG-APP-000170

Rule Version

FLYS-00-000090

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Fly Server Manager security configuration:
- Log on to Fly Server with an admin account.
- On the Management >> General Settings page, click the "Security Option" tab.
- Set Change Password setting, check option "New password cannot have consecutively same 8 characters as previous password".

Check Contents

Check the Fly Server Manager security configuration:
- Log on to Fly Server with an admin account.
- On the Management >> General Settings page, click the "Security Option" tab.
- Verify the Change Password setting is set to "New password cannot have consecutively same 8 characters as previous password".

If this option is unchecked, this is a finding.

Vulnerability Number

V-283934

Documentable

False

Rule Version

FLYS-00-000090

Severity Override Guidance

Check the Fly Server Manager security configuration:
- Log on to Fly Server with an admin account.
- On the Management >> General Settings page, click the "Security Option" tab.
- Verify the Change Password setting is set to "New password cannot have consecutively same 8 characters as previous password".

If this option is unchecked, this is a finding.

Check Content Reference

M

Target Key

5747