Skip to main content
CUI

LAB BASELINES - Findings

Back to Ship Export CSV Download POA&M
Switch to Flat View
Showing 44 unique vulnerabilities (444 total)
V-254512 CAT II Windows Server 2022 take ownership of files or other objects...
1 asset 1 Closed Microsoft Windows Se...
V-260465 CAT II Visual Search must be disabled.
1 asset 1 Closed Microsoft Edge Secur...
V-260466 CAT II Copilot must be disabled.
1 asset 1 Closed Microsoft Edge Secur...
V-260467 CAT II Session only-based cookies must be enabled.
1 asset 1 Closed Microsoft Edge Secur...
V-266981 CAT II FriendlyURLs must be disabled.
1 asset 1 Closed Microsoft Edge Secur...
V-268325 CAT II The Request Smuggling filter must be enabled.
1 asset 1 Closed Microsoft IIS 10.0 S...
V-271426 CAT II Windows Server 2022 must be configured for certificate-based...
1 asset Microsoft Windows Se...
V-271427 CAT II Windows Server 2022 must be configured for name-based strong...
1 asset Microsoft Windows Se...
V-278942 CAT II Windows Server 2022 must be configured to audit file system ...
1 asset 1 Closed Microsoft Windows Se...
V-278943 CAT II Windows Server 2022 must be configured to audit file system ...
1 asset 1 Closed Microsoft Windows Se...
V-278944 CAT II Windows Server 2022 must be configured to audit handle manip...
1 asset 1 Closed Microsoft Windows Se...
V-278945 CAT II Windows Server 2022 must be configured to audit handle manip...
1 asset 1 Closed Microsoft Windows Se...
V-278946 CAT II Windows Server 2022 must be configured to audit registry fai...
1 asset 1 Closed Microsoft Windows Se...
V-278947 CAT II Windows Server 2022 must be configured to audit registry suc...
1 asset 1 Closed Microsoft Windows Se...
V-278948 CAT II Windows Server 2022 must be configured to audit sensitive pr...
1 asset 1 Closed Microsoft Windows Se...
V-278949 CAT II Windows Server 2022 must be configured to audit sensitive pr...
1 asset 1 Closed Microsoft Windows Se...
V-278953 CAT II HTTPAPI Server version must be removed from the HTTP Respons...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-279940 CAT II Access to Microsoft 365 Copilot writing assistance must be d...
1 asset 1 Closed Microsoft Edge Secur...
V-218827 CAT III The IIS 10.0 web server must enable HTTP Strict Transport Se...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-225232 CAT III .Net applications that invoke NetFx40_LegacySecurityPolicy m...
1 asset Microsoft DotNet Fra...
V-225234 CAT III .NET default proxy settings must be reviewed and approved.
1 asset 1 Closed Microsoft DotNet Fra...
V-235719 CAT III User control of proxy settings must be disabled.
1 asset 1 Closed Microsoft Edge Secur...
V-235722 CAT III The list of domains for which Microsoft Defender SmartScreen...
1 asset 1 Closed Microsoft Edge Secur...
V-235727 CAT III Data Synchronization must be disabled.
1 asset 1 Closed Microsoft Edge Secur...
V-235731 CAT III Importing of browser settings must be disabled.
1 asset 1 Closed Microsoft Edge Secur...
V-235751 CAT III Edge development tools must be disabled.
1 asset 1 Closed Microsoft Edge Secur...
V-235752 CAT III Download restrictions must be configured.
1 asset 1 Closed Microsoft Edge Secur...
V-235753 CAT III URLs must be allowlisted for plugin use if used.
1 asset 1 Closed Microsoft Edge Secur...
V-235755 CAT III Extensions that are approved for use must be allowlisted if ...
1 asset 1 Closed Microsoft Edge Secur...
V-235765 CAT III The download location prompt must be configured.
1 asset 1 Closed Microsoft Edge Secur...
V-241789 CAT III ASP.NET version must be removed from the HTTP Response Heade...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-251694 CAT III The list of domains media autoplay allows must be allowliste...
1 asset 1 Closed Microsoft Edge Secur...
V-254255 CAT III Windows Server 2022 nonadministrative accounts or groups mus...
1 asset Microsoft Windows Se...
V-254281 CAT III The Windows Server 2022 time service must synchronize with a...
1 asset 1 Closed Microsoft Windows Se...
V-254335 CAT III Windows Server 2022 Internet Protocol version 6 (IPv6) sourc...
1 asset 1 Closed Microsoft Windows Se...
V-254336 CAT III Windows Server 2022 source routing must be configured to the...
1 asset 1 Closed Microsoft Windows Se...
V-254337 CAT III Windows Server 2022 must be configured to prevent Internet C...
1 asset 1 Closed Microsoft Windows Se...
V-254338 CAT III Windows Server 2022 must be configured to ignore NetBIOS nam...
1 asset 1 Closed Microsoft Windows Se...
V-254351 CAT III Windows Server 2022 Application Compatibility Program Invent...
1 asset 1 Closed Microsoft Windows Se...
V-254357 CAT III Windows Server 2022 Windows Update must not obtain updates f...
1 asset 1 Closed Microsoft Windows Se...
V-254363 CAT III Windows Server 2022 Turning off File Explorer heap terminati...
1 asset 1 Closed Microsoft Windows Se...
V-254400 CAT III Windows Server 2022 directory service must be configured to ...
1 asset Microsoft Windows Se...
V-254458 CAT III Windows Server 2022 title for legal banner dialog box must b...
1 asset 1 Closed Microsoft Windows Se...
V-254481 CAT III Windows Server 2022 default permissions of global system obj...
1 asset 1 Closed Microsoft Windows Se...
Page 9 of 9
CUI