Network misconfigurations

ALB outdated Security Policy

Description

An ALB listener is using an outdated security policy to negotiate SSL connections between the ALB and its clients. Outdated security policies may have known SSL/TLS flaws that an adversary can use to intercept HTTPS connections between the ALB and its clients.
  • Recommended Mitigation

    Ensure that all Application Load Balancers are using the latest predefined security policies. For more information, see: <a href="https://docs.aws.amazon.com/elasticloadbalancing/latest/classic/elb-security-policy-table.html" target="_blank" rel="noopener noreferrer">https://docs.aws.amazon.com/elasticloadbalancing/latest/classic/elb-security-policy-table.html</a>