1.10.1 ServiceOS Password

Information

This sequence descries enabling password authentication for ServiceOS login.

By default, the ServiceOS shell (accessible only from the local switch console port) requires no password to login as admin. This will allow un-privileged users with console access to log in to the ServiceOS shell.

Solution

Enable ServiceOS password authentication:

switch(config)# system serviceos password-prompt

Impact:

Enabling ServiceOS password authentication prevents unintended users from log into the ServiceOS shell, significantly reducing the risk of various security vulnerabilities and attacks.

See Also

https://workbench.cisecurity.org/benchmarks/24202

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, 800-53|IA-5(1), CSCv7|4.2, CSCv7|4.4

Plugin: ArubaOS

Control ID: 60c818d1e4a1875d366c92ad21e2bfbf08685eb1fd4c07fcb22e15b1d0e4f91c