4 ms·
"...the vulnerability was initially identified in 1990..." STIG scans are automated and the basis for identifying a finding is sometimes a lot different from t
by bitminer 8y ago
"...the vulnerability was initially identified in 1990..."
STIG scans are automated and the basis for identifying a finding is sometimes a lot different from the name. You have to decode the scanners script and compare the description with the code. In this case it is likely a "medium" finding that an email service is running and may be a risk. "May" and not "is". It requires a manual evaluation to confirm.
My favorite is the vulnerability identified as [redacted] which merely identifies the operating system as Windows. It is a High severity.
- siffland 8y agoI have to run STIGs all the time on 450+ linux systems being a Linux Admin and all. STIGs are a good starting point, however the word guidance is in their acronym for a reason. Other security has to be considered. At our facility we have a "check box" security department. The entity above us is so concerned about STIG findings and if they are checked of of the list, other vulnerabilities are left to the wayside. I once got in an argument about outdated embedded versions of java in applications we use. some were up to 7 years old. I advised that we contact vendors, but being an systems admin that was up to the individual application administrators. I was told it didn't show up on scans and to shut up and color (OK they were a little nicer to me than that, same message though). I can see how places might be lacking in security if they have the same mentality as here.