Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-3160 | NET0700 | SV-3160r4_rule | ECSC-1 | Medium |
Description |
---|
Network devices not running the latest tested and approved versions of software are vulnerable to network attacks. Running the most current, approved version of system and device software helps the site maintain a stable base of security fixes and patches, as well as enhancements to IP security. Viruses, denial of service attacks, system weaknesses, back doors and other potentially harmful situations could render a system vulnerable, allowing unauthorized access to DoD assets. |
STIG | Date |
---|---|
Perimeter Router Security Technical Implementation Guide | 2015-12-18 |
Check Text ( C-3549r4_chk ) |
---|
Have the administrator display the OS version in operation. The OS must be current with related IAVMs addressed. If the device is using an OS that does not meet all IAVMs or currently not supported by the vendor, this is a finding. |
Fix Text (F-3185r4_fix) |
---|
Update operating system to a supported version that addresses all related IAVMs. |