The Cisco ACI must not be configured to have any feature enabled that calls home to the vendor.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-272076CACI-RT-000016SV-272076r1168127_ruleCCI-002403medium
Description
Call home services will routinely send data such as configuration and diagnostic information to the vendor for routine or emergency analysis and troubleshooting. There is a risk that transmission of sensitive data sent to unauthorized persons could result in data loss or downtime due to an attack.
STIGDate
Cisco ACI Router Security Technical Implementation Guide2025-12-11

Related Frameworks

2 paths across 2 frameworks
NIST 800-531 mapping
  • DISA · V1R2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-002403
1.00
  • DISA · V1R2 · disa_xccdf · related

Details

Check Text (C-272076r1168127_chk)

Verify the ACI configuration under Admin >> External Data Collectors >> monitoring Destinations >> smart callhome/callhome is not setup, and that no Intersight configuration is setup at System >> System Settings >> Intersight Connectivity. If the Call Home feature is configured to send messages to unauthorized individuals such as Cisco TAC, this is a finding.

Fix Text (F-76033r1168126_fix)

Disable the Call Home feature: 1. Navigate to Admin >> External Data Collectors >> monitoring Destinations >> smart callhome. 2. In the General tab, set the Admin State to "Off". 3. Click "Save".