Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-49679 | AV-MOVE-SVA-10 | SV-62603r1_rule | High |
Description |
---|
The pre-configured Security Virtual Appliance (SVA) comes with a default password for the SVAadmin account. This account has root privileges to the Linux O/S of the appliance. By not changing the password from the default, the appliance will be subject to access by unauthorized individuals. |
STIG | Date |
---|---|
McAfee MOVE Agentless 3.0 Security Virtual Appliance STIG | 2015-10-06 |
Check Text ( C-51549r1_chk ) |
---|
Have the System Administrator confirm the default SVAadmin password has been change from the default of "admin". If the SVAadmin password has not been changed from the default of "admin", this is a finding. |
Fix Text (F-53181r1_fix) |
---|
Following local password change procedures for Linux systems, change the SVAadmin password from the default of "admin". |