Network misconfigurations

ELBv2 outdated Security Policy

Risk Level

Informational (4)

Platform(s)
Compliance Frameworks

Description

The listeners {AwsEc2Elbv2.Listeners} of the ELBv2 {AwsEc2Elbv2} are using an outdated security policy to negotiate SSL connections between the ELBv2 and its clients. Outdated security policies may have known SSL/TLS flaws that an adversary can use to intercept HTTPS connections between the ELBv2 and its clients.