Skip to main content
CUI

LAB BASELINES - Findings

Back to Ship Export CSV Download POA&M
Switch to Flat View
Showing 50 unique vulnerabilities (444 total)
V-218750 CAT I Anonymous IIS 10.0 website access accounts must be restricte...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218768 CAT I The IIS 10.0 private website must employ cryptographic mecha...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218795 CAT I All IIS 10.0 web server sample code, example applications, a...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218802 CAT I IIS 10.0 Web server accounts accessing the directory tree, t...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218821 CAT I An IIS 10.0 web server must maintain the confidentiality of ...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218823 CAT I All accounts installed with the IIS 10.0 web server software...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-235758 CAT I The version of Microsoft Edge running on the system must be ...
1 asset 1 Closed Microsoft Edge Secur...
V-254240 CAT I Windows Server 2022 administrative accounts must not be used...
1 asset 1 Closed Microsoft Windows Se...
V-254250 CAT I Windows Server 2022 local volumes must use a format that sup...
1 asset 1 Closed Microsoft Windows Se...
V-254262 CAT I Windows Server 2022 systems requiring data at rest protectio...
1 asset 1 Closed Microsoft Windows Se...
V-254293 CAT I Windows Server 2022 reversible password encryption must be d...
1 asset 1 Closed Microsoft Windows Se...
V-254352 CAT I Windows Server 2022 Autoplay must be turned off for nonvolum...
1 asset 1 Closed Microsoft Windows Se...
V-254353 CAT I Windows Server 2022 default AutoRun behavior must be configu...
1 asset 1 Closed Microsoft Windows Se...
V-254354 CAT I Windows Server 2022 AutoPlay must be disabled for all drives...
1 asset 1 Closed Microsoft Windows Se...
V-254374 CAT I Windows Server 2022 must disable the Windows Installer Alway...
1 asset 1 Closed Microsoft Windows Se...
V-254378 CAT I Windows Server 2022 Windows Remote Management (WinRM) client...
1 asset 1 Closed Microsoft Windows Se...
V-254381 CAT I Windows Server 2022 Windows Remote Management (WinRM) servic...
1 asset 1 Closed Microsoft Windows Se...
V-254385 CAT I Windows Server 2022 must only allow administrators responsib...
1 asset Microsoft Windows Se...
V-254391 CAT I Windows Server 2022 permissions on the Active Directory data...
1 asset Microsoft Windows Se...
V-254392 CAT I Windows Server 2022 Active Directory SYSVOL directory must h...
1 asset Microsoft Windows Se...
V-254393 CAT I Windows Server 2022 Active Directory Group Policy objects mu...
1 asset Microsoft Windows Se...
V-254394 CAT I Windows Server 2022 Active Directory Domain Controllers Orga...
1 asset Microsoft Windows Se...
V-254395 CAT I Windows Server 2022 organization created Active Directory Or...
1 asset Microsoft Windows Se...
V-254399 CAT I Windows Server 2022 directory data (outside the root DSE) of...
1 asset Microsoft Windows Se...
V-254413 CAT I Windows Server 2022 domain controller PKI certificates must ...
1 asset Microsoft Windows Se...
V-254414 CAT I Windows Server 2022 PKI certificates associated with user ac...
1 asset Microsoft Windows Se...
V-254428 CAT I Windows Server 2022 must only allow administrators responsib...
1 asset 1 Closed Microsoft Windows Se...
V-254441 CAT I Windows Server 2022 must be running Credential Guard on doma...
1 asset 1 Closed Microsoft Windows Se...
V-254446 CAT I Windows Server 2022 must prevent local accounts with blank p...
1 asset 1 Closed Microsoft Windows Se...
V-254465 CAT I Windows Server 2022 must not allow anonymous SID/Name transl...
1 asset 1 Closed Microsoft Windows Se...
V-254466 CAT I Windows Server 2022 must not allow anonymous enumeration of ...
1 asset 1 Closed Microsoft Windows Se...
V-254467 CAT I Windows Server 2022 must not allow anonymous enumeration of ...
1 asset 1 Closed Microsoft Windows Se...
V-254469 CAT I Windows Server 2022 must restrict anonymous access to Named ...
1 asset 1 Closed Microsoft Windows Se...
V-254474 CAT I Windows Server 2022 must be configured to prevent the storag...
1 asset 1 Closed Microsoft Windows Se...
V-254475 CAT I Windows Server 2022 LAN Manager authentication level must be...
1 asset 1 Closed Microsoft Windows Se...
V-254492 CAT I Windows Server 2022 Act as part of the operating system user...
1 asset 1 Closed Microsoft Windows Se...
V-254496 CAT I Windows Server 2022 create a token object user right must no...
1 asset 1 Closed Microsoft Windows Se...
V-254500 CAT I Windows Server 2022 debug programs user right must only be a...
1 asset 1 Closed Microsoft Windows Se...
V-218736 CAT II The IIS 10.0 website session state cookie settings must be c...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218737 CAT II A private IIS 10.0 website must only accept Secure Socket La...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218738 CAT II A public IIS 10.0 website must only accept Secure Socket Lay...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218739 CAT II Both the log file and Event Tracing for Windows (ETW) for ea...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218740 CAT II An IIS 10.0 website behind a load balancer or proxy server m...
1 asset Microsoft IIS 10.0 S...
V-218741 CAT II The IIS 10.0 website must produce log records that contain s...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218742 CAT II The IIS 10.0 website must produce log records containing suf...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218743 CAT II The IIS 10.0 website must have Multipurpose Internet Mail Ex...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218744 CAT II Mappings to unused and vulnerable scripts on the IIS 10.0 we...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218745 CAT II The IIS 10.0 website must have resource mappings set to disa...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218748 CAT II Each IIS 10.0 website must be assigned a default host header...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218749 CAT II A private IIS 10.0 website authentication mechanism must use...
1 asset 1 Closed Microsoft IIS 10.0 S...
Page 1 of 9
CUI