0% found this document useful (0 votes)
8 views11 pages

Short

The report presents the results of an internal authenticated vulnerability scan conducted for Circle Foods, revealing a 'C+' vulnerability risk posture with 1 critical, 89 high, 39 medium, and 3 low vulnerabilities. Key findings include the identification of the top root causes and vulnerabilities, emphasizing the need for urgent remediation to mitigate business risks. The scan, performed on January 26, 2026, highlighted the importance of monitoring open ports to minimize security threats.

Uploaded by

james.wilson
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views11 pages

Short

The report presents the results of an internal authenticated vulnerability scan conducted for Circle Foods, revealing a 'C+' vulnerability risk posture with 1 critical, 89 high, 39 medium, and 3 low vulnerabilities. Key findings include the identification of the top root causes and vulnerabilities, emphasizing the need for urgent remediation to mitigate business risks. The scan, performed on January 26, 2026, highlighted the importance of monitoring open ports to minimize security threats.

Uploaded by

james.wilson
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Executive Report

Internal Authenticated Vulnerability


Scan

Prepared for

Circle Foods

Assessment Period 01/27/2026

Reporting Date 01/27/2026 14:47:17


Table of Contents

Introduction

Executive Summary

Appendix

Top 10 Root Causes


Top 10 Vulnerabilities By Occurrence
Top 10 Most Vulnerable Machines
Introduction

Assessment Summary
This report provides an overview of the organization’s internal authenticated vulnerability scan results. The scan
was conducted to assess the security posture of internal systems and applications using authenticated access,
simulating an insider threat scenario.

The goal is to identify potential vulnerabilities that could be exploited by authenticated users to gain unauthorized
access or compromise sensitive data. New vulnerabilities are always being disclosed, so maintaining or reducing
overall vulnerability exposure is paramount.

Vulnerability Risk Rating


Vulnerabilities are broken down into four categories based on severity.
Severity levels are categorized as follows:

Vulnerabilities that pose a significant risk and could potentially lead to system compromise or
Critical
unauthorized access.
This represents a CVSS Score of 9.0 – 10.0

Vulnerabilities that have a substantial impact on the security of the system or application and
High
should be addressed urgently.
This represents a CVSS Score of 7.0 – 8.9

Vulnerabilities that have a moderate impact on the security of the system or application and
Medium
require timely attention.
This represents a CVSS Score of 4.0 – 6.9

Minor vulnerabilities that have a limited impact on the security of the system or application but
Low
should still be remediated.

This represents a CVSS Score of 0.0 – 3.9


Executive Summary

Explanation
This is a snapshot into the current vulnerability risk posture based on
Vulnerability Risk Score
vulnerabilities present across your IT environment.

A "C+" vulnerability risk posture means that vulnerabilities persist in


the environment exposing the organization to increased business risk.

C+ Further efforts must be made to contain and reduce the total number of
vulnerabilities to minimize business risk and ensure resiliency.

Identified Vulnerabilities by Severity

Critical High Medium Low

1 89 39 3

Scan Details

Scan Date 01/26/2026 09:16:41 UTC

Scan Duration 16 minutes

Targets Scanned 2 0 0
Open Port Vulnerabilities

Maintaining awareness of open ports across the network is essential for minimizing security risks and enhancing
our overall business resiliency. While open ports are often necessary for business operations, they can serve as
potential entry points for attackers, making it crucial to regularly review and assess which ports are accessible and
why.

Through continuous monitoring and audit of open ports, ensure that only necessary ports remain open to minimize
exposure to unauthorized access and mitigate potential threats.

Port Description Risk Level # of Targets

111 SUN Remote Procedure Call High 1

3389 MS Remote Desktop (RDP) High 1

80 World Wide Web HTTP Medium 1

139 NETBIOS Session Service Medium 1

445 Microsoft-DS Medium 1

135 DCE endpoint resolution Low 1

443 http protocol over TLS/SSL Low 1

1058 nim Low 1

2049 Low 1

2179 Microsoft RDP for virtual machines Low 1

10001 SCP Configuration Low 1

55056 MS Dynamic Ports Low 1


Appendix
Findings

Top 10 Root Causes

Root Cause Type Total Vulns Affected Assets Unique CVEs C H M L

Embedded Java (Process)


3rd Party 32 2 4 0 16 16 0
version

PowerEdge R440 3rd Party 11 1 11 0 3 5 3

Unclassified 3rd Party 11 1 11 0 3 5 3

UBR 3rd Party 4 1 4 0 2 2 0

C:\windows\System32 3rd Party 3 1 3 0 2 1 0

MS
Weak Cipher Suites Windows
2 2 1 0 2 0 0
enabled Server
2025

MS
WinTrust
Windows
EnableCertPaddingCheck 2 2 1 0 0 2 0
Server
disabled
2025
Top 10 Vulnerabilities by Occurrence

CVE Title CVSS Severity CVSS Score EPSS Probability Assets Affected

The host is installed with


Oracle Java SE through
8u471, 11.0.29, 17.0.17,
21.0.9, 25.0.1, Azul Zulu 6
before [Link], Azul Zulu 7
before [Link], Azul Zulu 8
before [Link], Azul Zulu
11 before 11.85.12, 17 before
17.63.12, 21 before 21.47.14,
or Amazon Corretto 8.x
before 8u482, Amazon
CVE-2026-21945 Corretto 11.x before 11.0.30, High 7.5 0.0004 2
17.x before 17.0.18, 21.x
before 21.0.10, 25.x before
25.0.2 and is prone to an
unspecified vulnerability. A
flaw is present in the
application, which fails to
handle vectors related to
Security. Successful
exploitation allows
attackers to affect
availability.

The host is installed with


Oracle Java SE through
8u471, 11.0.29, 17.0.17,
21.0.9, 25.0.1, Azul Zulu 6
before [Link], Azul Zulu 7
before [Link], Azul Zulu 8
before [Link], Azul Zulu
11 before 11.85.12, 17 before
17.63.12, 21 before 21.47.14,
or Amazon Corretto 8.x
before 8u482, Amazon
CVE-2026-21932 High 7.4 0.0003 2
Corretto 11.x before 11.0.30,
17.x before 17.0.18, 21.x
before 21.0.10, 25.x before
25.0.2 and is prone to an
unspecified vulnerability. A
flaw is present in the
application, which fails to
handle vectors related to
Networking. Successful
exploitation allows
attackers to affect integrity.

Self-Signed Self-signed certificate


High 7 0 2
Certificate detected

Weak Cipher Suites


CVE-CRSM-0001 High 7 0 2
enabled
CVE Title CVSS Severity CVSS Score EPSS Probability Assets Affected

The host is installed with


Oracle Java SE through
8u471, 11.0.29, 17.0.17,
21.0.9, 25.0.1, Azul Zulu 6
before [Link], Azul Zulu 7
before [Link], Azul Zulu 8
before [Link], Azul Zulu
11 before 11.85.12, 17 before
17.63.12, 21 before 21.47.14,
or Amazon Corretto 8.x
before 8u482, Amazon
CVE-2026-21933 Corretto 11.x before 11.0.30, Medium 6.1 0.0003 2
17.x before 17.0.18, 21.x
before 21.0.10, 25.x before
25.0.2 and is prone to an
unspecified vulnerability. A
flaw is present in the
application, which fails to
handle vectors related to
Networking. Successful
exploitation allows
attackers to affect
confidentiality and integrity.

WinVerifyTrust Signature
CVE-2013-3900 Medium 5.5 0.8049 2
Validation

The host is installed with


Oracle Java SE through
8u471, 11.0.29, 17.0.17,
21.0.9, 25.0.1, Azul Zulu 6
before [Link], Azul Zulu 7
before [Link], Azul Zulu 8
before [Link], Azul Zulu
11 before 11.85.12, 17 before
17.63.12, 21 before 21.47.14,
or Amazon Corretto 8.x
before 8u482, Amazon
CVE-2026-21925 Corretto 11.x before 11.0.30, Medium 4.8 0.0003 2
17.x before 17.0.18, 21.x
before 21.0.10, 25.x before
25.0.2 and is prone to an
unspecified vulnerability. A
flaw is present in the
application, which fails to
handle vectors related to
RMI. Successful
exploitation allows
attackers to affect
confidentiality and integrity.

The host is missing a


CVE-2024-55414 critical security update for Critical 9.8 0.005 1
KB5073379
CVE Title CVSS Severity CVSS Score EPSS Probability Assets Affected

The host is missing a


CVE-2026-20868 critical security update for High 8.8 0.001 1
KB5073379

Dell PowerEdge BIOS


contains an improper
privilege management
security vulnerability. An
CVE-2023-32460 unauthenticated local High 8.8 0.0005 1
attacker could potentially
exploit this vulnerability,
leading to privilege
escalation.
Top 10 Most Vulnerable Machines

Target Current Score Total Vulns C H M L

CFHV02 D+ 92 1 60 31 0

CFHV01 B 18 0 7 8 3

You might also like