STIGUI
V-284919CAT II — Medium severitySV-284919r1212118_rule

The Cisco SNA appliance must install security-relevant firmware updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs).

Rule version CSNA-ND-000770 · STIG v1 · 2026-07-08

Discussion

Security flaws with firmware are discovered daily. Vendors are constantly updating and patching their products to address newly discovered security vulnerabilities. Organizations (including any contractor to the organization) are required to promptly install security-relevant firmware updates. Flaws discovered during security assessments, continuous monitoring, incident response activities, or information system error handling must also be addressed expeditiously.

Check

Verify software updates are consistently applied to the Cisco SNA appliance within 30 days unless the time period is directed by an authoritative source.

Navigate to SNA Dashboard >> Configure >> Central Management >> Update Manager.

View the "Installed Version" for each appliance. Compare each one to the authoritative source version.

If the Cisco SNA appliance administrator does not install security-relevant updates within 30 days unless the time period is directed by an authoritative source, this is a finding.

Fix

Ensure patches are consistently applied to the Cisco SNA appliance within the time allowed.

Navigate to SNA Dashboard >> Configure >> Central Management >> Update Manager >> Upload Update File (previously downloaded from Cisco Software Central) >> Select Appliance >> Actions... >> Install Update.

Note: The SNA Manager should always be updated first to avoid versioning conflicts.

Identifiers

Group ID
V-284919
Group title
SRG-APP-000457-NDM-000352
Rule ID
SV-284919r1212118_rule
Check ID
C-89489r1212116_chk
Fix ID
F-89394r1212117_fix