Details
IPMI includes a hard-coded user named ‘ADMIN’ which cannot be disabled or removed. The password for this account must be strong to mitigate password-guessing attacks. The password is not visible in the appliance configuration.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Edit the configuration and enter this command:n
ipmi user set password
This security hardening control applies to the following category of controls within NIST 800-53: Access Control, Configuration Management.This control applies to the following type of system FireEye.