Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-251418 | IMIC-11-010800 | SV-251418r961683_rule | High |
Description |
---|
The UEM vendor maintains specific product versions for a specific period of time. MDM/EMM server versions no longer supported by the vendor will not receive security updates for new vulnerabilities, which leaves them subject to exploitation. Satisfies: FPT_TUD_EXT.1.1, FPT_TUD_EXT.1.2 Reference: PP-MDM-414005 |
STIG | Date |
---|---|
Ivanti MobileIron Core MDM Server Security Technical Implementation Guide | 2024-05-23 |
Check Text ( C-54853r806384_chk ) |
---|
Verify the Core server version is a supported version. This requirement is Not Applicable for the cloud version of Core. Find the list of currently supported on-prem versions of Core server here: https://help.ivanti.com/mi/help/en_us/EML/3.16.1/rni/Content/EmailPlusiOSReleaseNotes/Support_and_compatibilit.htm Log onto the Core console and determine the installed version of Core: 1. Click on the round person icon in the top right corner of the Core console. 2. In the drop-down menu, select "About". 3. View the version of Core that is installed. 4. Verify the version is a supported version. If the installed version of the Core server is not a supported version, this is a finding. |
Fix Text (F-54806r806385_fix) |
---|
Update Core to the most current version. If using the cloud version of Core, this requirement is automatically met. |