The operating system must be a version supported by the vendor.

STIG ID: SRG-OS-000830-GPOS-00300  |  SRG: SRG-OS-000830 |  Severity: high (CAT I)  |  CCI: CCI-003376 |  Vulnerability Id: V-278977

Vulnerability Discussion

Unsupported software and systems should not be used because fixes to newly identified bugs will not be implemented by the vendor. The lack of support can result in potential vulnerabilities.

Software and systems at unsupported servicing levels or releases will not receive security updates for new vulnerabilities, which leaves them subject to exploitation.

When maintenance updates and patches are no longer available, software is no longer considered supported and should be upgraded or decommissioned.

Check

Verify the operating system is a version supported by the vendor.

If the operating system is not a version supported by the vendor, this is a finding.

Fix

Install or upgrade the operating system to a version supported by the vendor.