Hi,
I recently dealt with around 80 instances of the TLS\SSL Beast Attack Vulnerability. I attempted to mitigate them by running a PowerShell script to disable SSL2, SSL3, TLS 1.0, and TLS 1.1. While this worked for most, 25 instances still show the vulnerability after a rescan.
Has anyone else encountered this same issue? I would appreciate any solutions or insights you might have.
Thanks
Hi jkrupcheck.
Were the 25 instances remaining part the of the same site and using the same scanning template? IVM vulnerabilities are cumulative so if for any reason it cannot scan on the port and service it will just show them as vulnerable with the same proof. I discovered this recently and found that the port they were showing vulnerable on (in our case custom RDP port) was caused by the port not being added to the device discovery port list.
If this is not the case, next check the proof in the asset to see where it is still reporting as vulnerable. If it is RDP ensure it is getting the correct configs, like enabling NLA, removing negotiation, forcing high security level, etc.
Finally if the proof doesn’t shed any light you may need enable enhanced logging temporarily in the scan template and then view the scan log.