Check: HP3P-32-001504
HPE 3PAR StoreServ 3.2.x STIG:
HP3P-32-001504
(in versions v2 r1 through v1 r2)
Title
User credentials which would allow remote access to the system by the Service Processor must be removed from the storage system. (Cat I impact)
Discussion
Failure to remove the default user accounts associated with remote access from the Service Processor increases the risk of unauthorized access to the 3PAR OS via the product's remote support interface. The Service Processor's authentication methods have not been evaluated and using such mechanisms to permit remote, full control of the system by organizational or non-organizational users represents an increased risk to unauthorized access. The Service Processor can also send system data offsite providing access to system information to non-DoD organizations.
Check Content
Verify Service Processor credentials are not present. cli% showuser If any of the users, "3parbrowse", "3paredit", or "3parservice" exist, this is a finding
Fix Text
Remove the Service Processor credentials from the storage system. Enter the following command: cli% removespcredential Note: This removes the "3paredit", "3parbrowse", and "3parservice" users, and sets the "3parsvc" password to a new random value.
Additional Identifiers
Rule ID: SV-237826r647903_rule
Vulnerability ID: V-237826
Group Title: SRG-OS-000125-GPOS-00065
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000877 |
Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions. |
Controls
Number | Title |
---|---|
MA-4 |
Nonlocal Maintenance |