STIGUI
V-286493CAT II — Medium severitySV-286493r1273760_rule

WTM must limit the number of concurrent sessions to eight or an organizationally identified limit.

Rule version AWTM-NM-000039 · STIG v1 · 2026-09-14

Discussion

Device management includes the ability to control the number of administrators and management sessions that manage a device. Limiting the number of allowed administrators and sessions per administrator based on account type, role, or access type is helpful in limiting risks related to denial-of-service (DoS) attacks.

This requirement addresses concurrent sessions for administrative accounts and does not address concurrent sessions by a single administrator via multiple administrative accounts. The maximum number of concurrent sessions must be defined based upon mission needs and the operational environment for each system. At a minimum, limits must be set for SSH, HTTPS, account of last resort, and root account sessions.

Check

1. Log in to the WTM Web UI. 2. Navigate to Admin >> User Management >> Login Control.

If the "User Session Limit" is not set to "8" or to the organization's acceptable user session limit, this is a finding.

Fix

1. Log in to the WTM Web UI. 2. Navigate to Admin >> User Management >> Login Control. 3. Click "Enable". 4. Set the "User Session Limit" to "8", or the organization's acceptable user session limit. 5. Click "Commit".

Identifiers

Group ID
V-286493
Group title
SRG-APP-000001-NDM-000200
Rule ID
SV-286493r1273760_rule
Check ID
C-91175r1273758_chk
Fix ID
F-91080r1273759_fix