Skip to main content
CUI

LAB BASELINES - Findings

Back to Ship Export CSV Download POA&M
Clear Filters Switch to Flat View
Showing 40 unique vulnerabilities (40 total) (filtered)
V-218795 CAT I All IIS 10.0 web server sample code, example applications, a...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218802 CAT I IIS 10.0 Web server accounts accessing the directory tree, t...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218821 CAT I An IIS 10.0 web server must maintain the confidentiality of ...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218823 CAT I All accounts installed with the IIS 10.0 web server software...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218786 CAT II Both the log file and Event Tracing for Windows (ETW) for th...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218788 CAT II The IIS 10.0 web server must produce log records that contai...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218789 CAT II The IIS 10.0 web server must produce log records containing ...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218791 CAT II The log data and records from the IIS 10.0 web server must b...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218792 CAT II The IIS 10.0 web server must not perform user management for...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218793 CAT II The IIS 10.0 web server must only contain functions necessar...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218794 CAT II The IIS 10.0 web server must not be both a website server an...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218796 CAT II The accounts created by uninstalled features (i.e., tools, u...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218797 CAT II The IIS 10.0 web server must be reviewed on a regular basis ...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218798 CAT II The IIS 10.0 web server must have Multipurpose Internet Mail...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218799 CAT II The IIS 10.0 web server must have Web Distributed Authoring ...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218801 CAT II Java software installed on a production IIS 10.0 web server ...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218803 CAT II The IIS 10.0 web server must separate the hosted application...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218804 CAT II The IIS 10.0 web server must use cookies to track session st...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218805 CAT II The IIS 10.0 web server must accept only system-generated se...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218806 CAT II The IIS 10.0 web server must augment re-creation to a stable...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218807 CAT II The production IIS 10.0 web server must utilize SHA2 encrypt...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218808 CAT II Directory Browsing on the IIS 10.0 web server must be disabl...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218810 CAT II Warning and error messages displayed to clients must be modi...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218812 CAT II The IIS 10.0 web server must restrict inbound connections fr...
1 asset Microsoft IIS 10.0 S...
V-218813 CAT II The IIS 10.0 web server must provide the capability to immed...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218814 CAT II IIS 10.0 web server system files must conform to minimum fil...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218815 CAT II The IIS 10.0 web server must use a logging mechanism configu...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218816 CAT II Access to web administration tools must be restricted to the...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218817 CAT II The IIS 10.0 web server must not be running on a system prov...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218818 CAT II The Internet Printing Protocol (IPP) must be disabled on the...
1 asset Microsoft IIS 10.0 S...
V-218819 CAT II The IIS 10.0 web server must be tuned to handle the operatio...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218820 CAT II IIS 10.0 web server session IDs must be sent to the client u...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218822 CAT II The IIS 10.0 web server must maintain the confidentiality of...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218824 CAT II Unspecified file extensions on a production IIS 10.0 web ser...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218825 CAT II The IIS 10.0 web server must have a global authorization rul...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218826 CAT II The IIS 10.0 websites MaxConnections setting must be configu...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-228572 CAT II An IIS Server configured to be a SMTP relay must require aut...
1 asset Microsoft IIS 10.0 S...
V-268325 CAT II The Request Smuggling filter must be enabled.
1 asset 1 Closed Microsoft IIS 10.0 S...
V-218827 CAT III The IIS 10.0 web server must enable HTTP Strict Transport Se...
1 asset 1 Closed Microsoft IIS 10.0 S...
V-241789 CAT III ASP.NET version must be removed from the HTTP Response Heade...
1 asset 1 Closed Microsoft IIS 10.0 S...
CUI