UCF STIG Viewer Logo

The Cisco switch must be configured to implement replay-resistant authentication mechanisms for network access to privileged accounts.


Overview

Finding ID Version Rule ID IA Controls Severity
V-220488 CISC-ND-000530 SV-220488r929031_rule Medium
Description
A replay attack may enable an unauthorized user to gain access to the application. Authentication sessions between the authenticator and the application validating the user credentials must not be vulnerable to a replay attack. An authentication process resists replay attacks if it is impractical to achieve a successful authentication by recording and replaying a previous authentication message.
STIG Date
Cisco NX OS Switch NDM Security Technical Implementation Guide 2023-11-28

Details

Check Text ( C-22203r929029_chk )
Verify that FIPS mode is enabled as shown in the example below:

show fips status

Note: Cisco NX-OS software supports only SSH version 2 (SSHv2). Beginning in Cisco NX-OS Release 5.1, SSH runs in FIPS mode. Source: Cisco Nexus 7000 Series NX-OS Security Configuration Guide, Release 6.x.

If the switch is not configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions, this is a finding.
Fix Text (F-22192r929030_fix)
Enable fips mode via the command "fips mode enable".

Note: The switch will require a reboot for fips mode to be enabled.