The VMM must store only encrypted representations of passwords.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-207376SRG-OS-000073SRG-OS-000073-VMM-000400SV-207376r984199_rule2025-09-102

Description

Passwords need to be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised.

ℹ️ Check

Verify the VMM stores only encrypted representations of passwords. If it does not, this is a finding.

✔️ Fix

Configure the VMM to store only encrypted representations of passwords.