Rule version BCAS-ND-001940 · STIG v1 · 2026-09-16
Network devices running an unsupported operating system lack current security fixes required to mitigate the risks associated with recent vulnerabilities.
Satisfies: SRG-APP-000516-NDM-000351, SRG-APP-000457-NDM-000352, SRG-APP-001035-NDM-000340
Verify the CAS release version is at a vendor-supported level with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "show version". 3. Compare the running version against the list of supported versions found at: https://support.broadcom.com/group/ecx/products.
If the "CAS release" version is no longer supported by the vendor (end of life/end of support), this is a finding.
Configure CAS to a vendor-supported release version with the following steps:
1. Log on to the Broadcom Symantec Support Portal at https://support.broadcom.com/group/ecx/products. 2. Click "My Downloads" and select "Cyber Security Software". 3. Search for "Content Analysis System" or "CAS" from the software downloads. 4. Expand the product list and select the appropriate hardware model or virtual appliance type. 5. Select a supported software build and download the image file. 6. Log on to the CAS Web Management Console. 7. Navigate to Settings >> Maintenance >> Systems and Upgrades. 8. Upload the downloaded image and select "Install". 9. Once the installation is complete, select the new version and click "Restart" to boot into the supported release.