Network misconfigurations

ELBv2 outdated Security Policy

Description

The listeners {AwsEc2Elbv2.Listeners} of the ELBv2 {AwsEc2Elbv2} are using an outdated security policy to negotiate SSL connections between the ELBv2 and its clients. Outdated security policies may have known SSL/TLS flaws that an adversary can use to intercept HTTPS connections between the ELBv2 and its clients.
  • Recommended Mitigation

    Ensure that your ELBv2 load balancers are using the latest predefined security policies. Learn more here: <a href="https://docs.aws.amazon.com/elasticloadbalancing/latest/classic/elb-security-policy-table.html" target="_blank" rel="noopener noreferrer">https://docs.aws.amazon.com/elasticloadbalancing/latest/classic/elb-security-policy-table.html</a>