STIGQter STIGQter: STIG Summary: AvePoint Fly Server Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

Fly Server must enforce 24 hours/1 day as the minimum password lifetime.

DISA Rule

SV-283935r1206159_rule

Vulnerability Number

V-283935

Group Title

SRG-APP-000173

Rule Version

FLYS-00-000095

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Fly Server Manager security configuration:
- Log on to Fly Server with an admin account.
- On the Management >> General Settings page, click the "Security Option" tab.
- Check "Change the password once only within 24 hours" to set the Change Password setting.

Check Contents

Check the Fly Server Manager security configuration:
- Log on to Fly Server with an admin account.
- On the Management >> General Settings page, click the "Security Option" tab.
- Verify the Change Password setting option "Change the password once only within 24 hours" is checked.

If this option is unchecked, this is a finding.

Vulnerability Number

V-283935

Documentable

False

Rule Version

FLYS-00-000095

Severity Override Guidance

Check the Fly Server Manager security configuration:
- Log on to Fly Server with an admin account.
- On the Management >> General Settings page, click the "Security Option" tab.
- Verify the Change Password setting option "Change the password once only within 24 hours" is checked.

If this option is unchecked, this is a finding.

Check Content Reference

M

Target Key

5747