The NSX Manager must not provide environment information to third parties.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-265349NMGR-4X-000088SV-265349r994270_ruleCCI-000366low
Description
Providing technical details about an environment's infrastructure to third parties could unknowingly expose sensitive information to bad actors if intercepted.
STIGDate
VMware NSX 4.x Manager NDM Security Technical Implementation Guide2024-12-13

Related Frameworks

4 paths across 3 frameworks
NIST 800-531 mapping
CM-6
1.00
  • DISA · V1R2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1712 mappings
3.4.1
1.00
  • DISA · V1R2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.4.2
1.00
  • DISA · V1R2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000366
1.00
  • DISA · V1R2 · disa_xccdf · related

Details

Check Text (C-265349r994270_chk)

From the NSX Manager web interface, go to System >> Settings >> General Settings >> Customer Program >> Customer Experience Improvement Program. If Joined is set to "Yes", this is a finding.

Fix Text (F-69174r994269_fix)

From the NSX Manager web interface, go to System >> Settings >> General Settings >> Customer Program >> Customer Experience Improvement Program, and then click "Edit". Uncheck "Join the VMware Customer Experience Improvement Program" and click "Save".