1.1.6 Default admin account password

Information

The AOS-CX switches ship with a built-in, default user account named 'admin'. In accordance with the 2020 California password law, AOS-CX switches require that customers set the password for this built-in user account at first login.

The setting of a strong password for all built-in user account is necessary for any device.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

If a customer fails to set a strong password for the built-in 'admin' user account, he/she can set the password using the following command:

switch(config)# user admin password
Enter password: ************
Confirm password: ************
switch(config)#

Impact:

AOS-CX devices will force customers to set a password for the built-in 'admin' user account upon first login. It's important that customers abide by this behavior to ensure that their device isn't deployed with a weak or empty password.

See Also

https://workbench.cisecurity.org/benchmarks/24202

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CSCv7|4.2

Plugin: ArubaOS

Control ID: 9e6cda681fcd5980763f83e282f60101ae4c657f8ae56d0fd4497e63653a7aef