Check: GEN000680
VMware ESX 3 Server:
GEN000680
(in version v1 r2)
Title
The system must require passwords to contain no more than three consecutive repeating characters. (Cat II impact)
Discussion
To enforce the use of complex passwords, the number of consecutive repeating characters is limited. Passwords with excessive repeated characters may be more vulnerable to password-guessing attacks.
Check Content
Verify the system requires passwords to contain no more than three consecutive repeating characters. If the system allows passwords to contain more than three consecutive repeating characters, this is a finding.
Fix Text
Configure the system to require passwords to contain no more than three consecutive repeating characters.
Additional Identifiers
Rule ID: SV-12476r2_rule
Vulnerability ID: V-11975
Group Title: GEN000680
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |