Network misconfigurations

ALB outdated Security Policy

Platform(s)
Compliance Frameworks

CCPA, cis_8, CPRA, essential_8_au, essential_8_au_level_1, essential_8_au_level_2, iso_27001_2022, iso_27002_2022, Mitre ATT&CK, New Zealand Information Security Manual, NIST 800-171, NIST 800-53, Orca Best Practices, PDPA, UK Cyber Essentials

Description

An ALB listener is using an outdated security policy to negotiate SSL connections between the ALB and its clients. Outdated security policies may have known SSL/TLS flaws that an adversary can use to intercept HTTPS connections between the ALB and its clients.