1.1.1 Ensure 'Logon Password' is set

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Changes the default login password.

Rationale:

The login password is used for Telnet and SSH connections. The default device configuration does not require any strong user authentication enabling unfettered access to an attacker that can reach the device. A user can enter the default password and just press the Enter key at the Password prompt to login to the device. Setting the login password causes the device to enforce use of a strong password to access user mode. Using default or well-known passwords makes it easier for an attacker to gain entry to a device.

Solution

Run the following to set the login password.

hostname(config)#PASSWD _<login_password>_

The login_password parameter should be the plain-text password used to log into the system

See Also

https://benchmarks.cisecurity.org/tools2/cisco/CIS_Cisco_Firewall_Benchmark_v4.0.0.pdf

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CSCv6|16.13, CSCv6|16.14

Plugin: Cisco

Control ID: 6dad6c7ae2b8db8e6adac0a2c706dc242ec9cd0463708c91e9619b8bd9331a3b