Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-258613 | IVCS-NM-000410 | SV-258613r930527_rule | High |
Description |
---|
Network devices running an unsupported operating system lack current security fixes required to mitigate the risks associated with recent vulnerabilities. |
STIG | Date |
---|---|
Ivanti Connect Secure NDM Security Technical Implementation Guide | 2023-10-17 |
Check Text ( C-62353r930525_chk ) |
---|
Navigate to the ICS support site https://my.pulsesecure.net/. 1. Login using the valid support login. 2. Click the link for "Software Licensing and Download". 3. Click "License and System Download". 4. Click "Software Download". 5. Under "Product Lines", click "Pulse Connect Secure" and again, "Pulse Connect Secure". 6. Click the "End of Support" tab. 7. Now using the ICS Web UI, navigate to Maintenance >> System >> Platform. If the version running under Current Version is on the list of End of Support images on the Ivanti support site, this is a finding. |
Fix Text (F-62262r930526_fix) |
---|
Navigate to the ICS support site https://my.pulsesecure.net/. 1. Login using the valid support login. 2. Click the link for "Software Licensing and Download". 3. Click either virtual or physical appliance. 4. Click "Software Download". 5. Under Product Lines, click "Pulse Connect Secure" and again, "Pulse Connect Secure". 6. Click "Current and Supported Releases". 7. Click "Download" on the latest ICS images. Using the ICS Web UI navigate to Maintenance >> System >> Upgrade/Downgrade. 1. Ensure the ICS is upgraded in accordance with the site's change management and change control policies, as this will cause a platform outage. 2. Under "Install Service Package" click "Browse" and select the recently downloaded images. 3. Click "Install". 4. Follow all prompts for the upgrading the new images. |