UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The HP FlexFabric Switch must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.


Overview

Finding ID Version Rule ID IA Controls Severity
V-66155 HFFS-ND-000015 SV-80645r1_rule Medium
Description
By limiting the number of failed logon attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced.
STIG Date
HP FlexFabric Switch NDM Security Technical Implementation Guide 2020-06-03

Details

Check Text ( C-66801r1_chk )
Verify that the HP FlexFabric Switch is configured to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.

[HP] display password-control

Global password control configurations:
Maximum login attempts: 3
Action for exceeding login attempts: Lock user for 15 minutes

If the limit of three consecutive invalid logon attempts by a user during a 15-minute time period is not enforced, this is a finding.
Fix Text (F-72231r1_fix)
Configure the HP FlexFabric Switch to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period:

[HP]password-control login-attempt 3 exceed lock-time 15