St Luke's- 192.168.9.0 Vulnerability scanner

Report generated by Nessus™ Thu, 05 Dec 2019 13:15:24 GMT Standard Time TABLE OF CONTENTS

Hosts Executive Summary • 192.168.9.20...... 7 • 192.168.9.23...... 8 • 192.168.9.52...... 9 • 192.168.9.53...... 10 • 192.168.9.56...... 11 • 192.168.9.59...... 12 • 192.168.9.60...... 13 • 192.168.9.61...... 14 • 192.168.9.62...... 15 • 192.168.9.63...... 16 • 192.168.9.64...... 17 • 192.168.9.67...... 18 • 192.168.9.69...... 19 • 192.168.9.72...... 20 • 192.168.9.73...... 21 • 192.168.9.80...... 22 • 192.168.9.81...... 23 • 192.168.9.85...... 24 • 192.168.9.86...... 25 • 192.168.9.88...... 26 • 192.168.9.89...... 27 • 192.168.9.100...... 28 • 192.168.9.102...... 29 • 192.168.9.104...... 30 • 192.168.9.106...... 31 • 192.168.9.108...... 32 • 192.168.9.110...... 33 • 192.168.9.111...... 34 • 192.168.9.112...... 35 • 192.168.9.113...... 36 • 192.168.9.116...... 37 • 192.168.9.137...... 39 • 192.168.9.139...... 40 • 192.168.9.178...... 41 • 192.168.9.201...... 42 • 192.168.9.205...... 43 • 192.168.9.234...... 44 • 192.168.9.235...... 45 • 192.168.9.242...... 46 • 192.168.9.254...... 49 • Deploy-01...... 50 • HAVOC...... 51 • Venom...... 55 • WSUS1...... 57 • attacker...... 58 • bearcat...... 59 • beaumont.tc.stlukes-hospice.org.uk...... 62 • beaumontipmi.tc.stlukes-hospice.org.uk...... 63 • besx1.tc.stlukes-hospice.org.uk...... 64 • besx2.tc.stlukes-hospice.org.uk...... 65 • blackbird.tc.stlukes-hospice.org.uk...... 66 • blvault1.tc.stlukes-hospice.org.uk...... 68 • buccaneer.tc.stlukes-hospice.org.uk...... 69 • camm.tc.stlukes-hospice.org.uk...... 70 • catalina.tc.stlukes-hospice.org.uk...... 71 • dakota.tc.stlukes-hospice.org.uk...... 75 • eras1.tc.stlukes-hospice.org.uk...... 81 • esx1.tc.stlukes-hospice.org.uk...... 82 • esx2.tc.stlukes-hospice.org.uk...... 83 • esx3.tc.stlukes-hospice.org.uk...... 84 • galaxy.tc.stlukes-hospice.org.uk...... 85 • harrier.tc.stlukes-hospice.org.uk...... 86 • hart...... 87 • hunter.tc.stlukes-hospice.org.uk...... 88 • hurricane.tc.stlukes-hospice.org.uk...... 89 • jaguar...... 90 • jaguar-test...... 92 • liberator.tc.stlukes-hospice.org.uk...... 94 • lightning.tc.stlukes-hospice.org.uk...... 95 • meteor...... 97 • mitchell.tc.stlukes-hospice.org.uk...... 100 • nas4free2.tc.stlukes-hospice.org.uk...... 101 • parallels.stlukes-hospice.org.uk...... 102 • phantom.tc.stlukes-hospice.org.uk...... 103 • quillipmi.tc.stlukes-hospice.org.uk...... 104 • raptor.tc.stlukes-hospice.org.uk...... 105 • sabre.tc.stlukes-hospice.org.uk...... 106 • tcvault1.tc.stlukes-hospice.org.uk...... 107 • tempest.tc.stlukes-hospice.org.uk...... 108 • thunderbolt.tc.stlukes-hospice.org.uk...... 109 • tigercat...... 110 • timetools.tc.stlukes-hospice.org.uk...... 112 • untangle.tc.stlukes-hospice.org.uk...... 113 • unwinipmi.tc.stlukes-hospice.org.uk...... 114 • vampire.tc.stlukes-hospice.org.uk...... 115 • vcs1.tc.stlukes-hospice.org.uk...... 116 • vcs2.tc.stlukes-hospice.org.uk...... 117 • wap1.stlukes-hospice.org.uk...... 118 Hosts Executive Summary 192.168.9.20

0 1 4 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 5

SEVERITY CVSS PLUGIN NAME

HIGH 7.5 41028 SNMP Agent Default Community Name (public)

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.8 42263 Unencrypted Telnet Server

MEDIUM 5.0 76474 SNMP 'GETBULK' Reflection DDoS

MEDIUM 4.3 71174 RomPager HTTP Referer Header XSS

192.168.9.20 7 192.168.9.23

0 1 4 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 5

SEVERITY CVSS PLUGIN NAME

HIGH 7.5 41028 SNMP Agent Default Community Name (public)

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.8 42263 Unencrypted Telnet Server

MEDIUM 5.0 76474 SNMP 'GETBULK' Reflection DDoS

MEDIUM 4.3 71174 RomPager HTTP Referer Header XSS

192.168.9.23 8 192.168.9.52

0 1 0 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 1

SEVERITY CVSS PLUGIN NAME

HIGH 7.5 41028 SNMP Agent Default Community Name (public)

192.168.9.52 9 192.168.9.53

0 0 1 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 1

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 42263 Unencrypted Telnet Server

192.168.9.53 10 192.168.9.56

0 0 1 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 1

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 42263 Unencrypted Telnet Server

192.168.9.56 11 192.168.9.59

0 0 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 2

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.8 42263 Unencrypted Telnet Server

192.168.9.59 12 192.168.9.60

0 1 5 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 6

SEVERITY CVSS PLUGIN NAME

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.8 42263 Unencrypted Telnet Server

MEDIUM 5.0 15901 SSL Certificate Expiry

192.168.9.60 13 192.168.9.61

0 1 5 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 6

SEVERITY CVSS PLUGIN NAME

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.8 42263 Unencrypted Telnet Server

MEDIUM 5.0 15901 SSL Certificate Expiry

192.168.9.61 14 192.168.9.62

0 0 4 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 4

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.8 42263 Unencrypted Telnet Server

MEDIUM 5.0 121007 SSH Known Hard Coded Private Keys

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

192.168.9.62 15 192.168.9.63

0 0 3 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 3

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.8 42263 Unencrypted Telnet Server

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

192.168.9.63 16 192.168.9.64

0 0 3 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 3

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.8 42263 Unencrypted Telnet Server

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

192.168.9.64 17 192.168.9.67

0 0 3 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 3

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.8 42263 Unencrypted Telnet Server

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

192.168.9.67 18 192.168.9.69

0 0 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 2

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.8 42263 Unencrypted Telnet Server

192.168.9.69 19 192.168.9.72

0 0 1 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 1

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 42263 Unencrypted Telnet Server

192.168.9.72 20 192.168.9.73

0 0 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 2

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.8 42263 Unencrypted Telnet Server

192.168.9.73 21 192.168.9.80

0 1 6 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 7

SEVERITY CVSS PLUGIN NAME

HIGH 7.5 41028 SNMP Agent Default Community Name (public)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.8 42880 SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection

MEDIUM 5.8 42263 Unencrypted Telnet Server

MEDIUM 5.0 76474 SNMP 'GETBULK' Reflection DDoS

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

192.168.9.80 22 192.168.9.81

0 1 5 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 6

SEVERITY CVSS PLUGIN NAME

HIGH 7.5 41028 SNMP Agent Default Community Name (public)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.8 42880 SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection

MEDIUM 5.0 76474 SNMP 'GETBULK' Reflection DDoS

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

192.168.9.81 23 192.168.9.85

0 1 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 3

SEVERITY CVSS PLUGIN NAME

HIGH 7.5 41028 SNMP Agent Default Community Name (public)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

192.168.9.85 24 192.168.9.86

0 0 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 2

SEVERITY CVSS PLUGIN NAME

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

192.168.9.86 25 192.168.9.88

0 0 3 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 3

SEVERITY CVSS PLUGIN NAME

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

192.168.9.88 26 192.168.9.89

1 0 3 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 4

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 119780 Netatalk OpenSession Remote Code Execution

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

192.168.9.89 27 192.168.9.100

0 1 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 3

SEVERITY CVSS PLUGIN NAME

HIGH 7.5 41028 SNMP Agent Default Community Name (public)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

192.168.9.100 28 192.168.9.102

0 1 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 3

SEVERITY CVSS PLUGIN NAME

HIGH 7.5 41028 SNMP Agent Default Community Name (public)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

192.168.9.102 29 192.168.9.104

1 1 4 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 6

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 93650 Dropbear SSH Server < 2016.72 Multiple Vulnerabilities

HIGH 7.8 80101 IPMI v2.0 Password Hash Disclosure

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

192.168.9.104 30 192.168.9.106

3 2 10 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 15

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 93650 Dropbear SSH Server < 2016.72 Multiple Vulnerabilities

CRITICAL 10.0 64394 Portable SDK for UPnP Devices (libupnp) < 1.6.18 Multiple Stack-based Buffer Overflows RCE

CRITICAL 10.0 76213 SuperMicro IPMI PSBlock File Plaintext Password Disclosure

HIGH 7.8 80101 IPMI v2.0 Password Hash Disclosure

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 43156 NTP ntpd Mode 7 Error Response Packet Loop Remote DoS

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.8 42880 SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection

MEDIUM 5.0 97861 Network Time Protocol (NTP) Mode 6 Scanner

MEDIUM 5.0 71783 Network Time Protocol Daemon (ntpd) monlist Command Enabled DoS

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.3 26928 SSL Weak Cipher Suites Supported

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

192.168.9.106 31 192.168.9.108

1 2 11 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 14

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 93650 Dropbear SSH Server < 2016.72 Multiple Vulnerabilities

HIGH 7.8 80101 IPMI v2.0 Password Hash Disclosure

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 43156 NTP ntpd Mode 7 Error Response Packet Loop Remote DoS

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.8 42880 SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection

MEDIUM 5.8 71534 SuperMicro Device Uses Default SSL Certificate

MEDIUM 5.0 97861 Network Time Protocol (NTP) Mode 6 Scanner

MEDIUM 5.0 71783 Network Time Protocol Daemon (ntpd) monlist Command Enabled DoS

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.3 26928 SSL Weak Cipher Suites Supported

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

192.168.9.108 32 192.168.9.110

0 0 1 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 1

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 42263 Unencrypted Telnet Server

192.168.9.110 33 192.168.9.111

0 1 7 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 8

SEVERITY CVSS PLUGIN NAME

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

192.168.9.111 34 192.168.9.112

0 0 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 2

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.0 10061 Echo Service Detection

192.168.9.112 35 192.168.9.113

0 0 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 2

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.0 10061 Echo Service Detection

192.168.9.113 36 192.168.9.116

2 5 10 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 17

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 100760 KB4022715: Version 1607 and Windows Server 2016 June 2017 Cumulative Update

CRITICAL 10.0 128530 Mozilla Firefox ESR < 60.9

HIGH 9.3 106796 KB4074590: Windows 10 Version 1607 and Windows Server 2016 February 2018 Security Update (Meltdown)(Spectre)

HIGH 9.3 111685 KB4343887: Windows 10 Version 1607 and Windows Server 2016 August 2018 Security Update ()

HIGH 7.6 105548 KB4056890: Windows 10 Version 1607 and Windows Server 2016 January 2018 Security Update (Meltdown)(Spectre)

HIGH 7.5 128080 VLC < 3.0.8 Multiple Vulnerabilities

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.4 112116 Security Updates for Windows 10 / Windows Server 2016 (August 2018) (Spectre) (Meltdown) (Foreshadow)

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.7 121035 Security Updates for Windows 10 / Windows Server 2016 (January 2019) (Spectre)

192.168.9.116 37 MEDIUM 4.7 119239 Security Updates for Windows 10 / Windows Server 2016 (September 2018) (Spectre)

192.168.9.116 38 192.168.9.137

0 0 3 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 3

SEVERITY CVSS PLUGIN NAME

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

192.168.9.137 39 192.168.9.139

2 4 8 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 14

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 100760 KB4022715: Windows 10 Version 1607 and Windows Server 2016 June 2017 Cumulative Update

CRITICAL 10.0 64784 SQL Server Unsupported Version Detection

HIGH 9.3 106796 KB4074590: Windows 10 Version 1607 and Windows Server 2016 February 2018 Security Update (Meltdown)(Spectre)

HIGH 9.3 111685 KB4343887: Windows 10 Version 1607 and Windows Server 2016 August 2018 Security Update (Foreshadow)

HIGH 9.3 125058 KB4494440: Windows 10 Version 1607 and Windows Server 2016 May 2019 Security Update (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)

HIGH 7.6 105548 KB4056890: Windows 10 Version 1607 and Windows Server 2016 January 2018 Security Update (Meltdown)(Spectre)

MEDIUM 6.8 130170 Mozilla Firefox < 70.0 Multiple Vulnerabilities

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.7 121035 Security Updates for Windows 10 / Windows Server 2016 (January 2019) (Spectre)

192.168.9.139 40 192.168.9.178

0 0 1 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 1

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 42263 Unencrypted Telnet Server

192.168.9.178 41 192.168.9.201

1 2 7 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 10

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 93650 Dropbear SSH Server < 2016.72 Multiple Vulnerabilities

HIGH 7.8 80101 IPMI v2.0 Password Hash Disclosure

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.8 42880 SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.3 26928 SSL Weak Cipher Suites Supported

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

192.168.9.201 42 192.168.9.205

0 0 3 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 3

SEVERITY CVSS PLUGIN NAME

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.8 42263 Unencrypted Telnet Server

192.168.9.205 43 192.168.9.234

0 1 5 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 6

SEVERITY CVSS PLUGIN NAME

HIGH 7.5 41028 SNMP Agent Default Community Name (public)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 76474 SNMP 'GETBULK' Reflection DDoS

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

192.168.9.234 44 192.168.9.235

1 0 4 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 5

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 119780 Netatalk OpenSession Remote Code Execution

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

192.168.9.235 45 192.168.9.242

8 10 23 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 41

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 72704 Microsoft .NET Framework Unsupported

CRITICAL 10.0 22024 Microsoft Internet Explorer Unsupported Version Detection

CRITICAL 10.0 64784 Microsoft SQL Server Unsupported Version Detection

CRITICAL 10.0 100791 Microsoft Security Advisory 4025685: Guidance for older platforms (XP / 2003) (EXPLODINGCAN)

CRITICAL 10.0 84729 Server 2003 Unsupported Installation Detection

CRITICAL 10.0 62758 Microsoft XML Parser (MSXML) and XML Core Services Unsupported

CRITICAL 10.0 40362 Mozilla Foundation Unsupported Application Detection

CRITICAL 10.0 108797 Unsupported Windows OS (remote)

HIGH 9.3 48762 MS KB2269637: Insecure Library Loading Could Allow Remote Code Execution

HIGH 9.3 53382 MS11-025: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)

HIGH 9.3 61535 MS12-060: Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2720573)

HIGH 9.3 100464 Microsoft Windows SMBv1 Multiple Vulnerabilities

HIGH 9.3 100782 Security Update for Microsoft Office Products (June 2017)

HIGH 8.5 84738 MS15-058: Vulnerabilities in SQL Server Could Allow Remote Code Execution (3065718)

HIGH 8.3 81264 MS15-011: Vulnerability in Could Allow Remote Code Execution (3000483)

HIGH 7.5 21564 VNC Security Type Enforcement Failure Remote Authentication Bypass

192.168.9.242 46 HIGH 7.2 69557 Novell Client / Client 2 Multiple Vulnerabilities

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.9 58333 MS12-021: Vulnerability in Visual Studio Could Allow Elevation of Privilege (2651019)

MEDIUM 6.9 83355 MS15-050: Vulnerability in Service Control Manager Could Allow Elevation of Privilege (3055642)

MEDIUM 6.8 48761 MS KB982316: Elevation of Privilege Using Windows Service Isolation Bypass

MEDIUM 6.8 63478 Microsoft Windows LM / NTLMv1 Authentication Enabled

MEDIUM 6.8 103876 Microsoft Windows SMB Server (2017-10) Multiple Vulnerabilities (uncredentialed check)

MEDIUM 6.8 130170 Mozilla Firefox < 70.0 Multiple Vulnerabilities

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 6.1 80494 MS15-005: Vulnerability in Network Location Awareness Service Could Allow Security Feature Bypass (3022777)

MEDIUM 5.8 87252 MS KB3123040: Improperly Issued Digital Certificates Could Allow Spoofing

MEDIUM 5.8 90510 MS16-047: Security Update for SAM and LSAD Remote Protocols (3148527) () (uncredentialed check)

MEDIUM 5.0 26920 Microsoft Windows SMB NULL Session Authentication

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.7 105613 ADV180002: Microsoft SQL Server January 2018 Security Update (Meltdown) (Spectre)

MEDIUM 4.3 78447 MS KB3009008: Vulnerability in SSL 3.0 Could Allow Information Disclosure (POODLE)

192.168.9.242 47 MEDIUM 4.3 55129 MS11-049: Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure (2543893)

MEDIUM 4.3 77162 MS14-044: Vulnerability in SQL Server Could Allow Elevation of Privilege (2984340)

MEDIUM 4.3 26928 SSL Weak Cipher Suites Supported

MEDIUM 4.3 81606 SSL/TLS EXPORT_RSA <= 512-bit Cipher Suites Supported (FREAK)

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

192.168.9.242 48 192.168.9.254

0 0 1 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 1

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 50686 IP Forwarding Enabled

192.168.9.254 49 Deploy-01

1 3 8 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 12

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 100760 KB4022715: Windows 10 Version 1607 and Windows Server 2016 June 2017 Cumulative Update

HIGH 9.3 106796 KB4074590: Windows 10 Version 1607 and Windows Server 2016 February 2018 Security Update (Meltdown)(Spectre)

HIGH 9.3 111685 KB4343887: Windows 10 Version 1607 and Windows Server 2016 August 2018 Security Update (Foreshadow)

HIGH 7.6 105548 KB4056890: Windows 10 Version 1607 and Windows Server 2016 January 2018 Security Update (Meltdown)(Spectre)

MEDIUM 6.8 130170 Mozilla Firefox < 70.0 Multiple Vulnerabilities

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.4 112116 Security Updates for Windows 10 / Windows Server 2016 (August 2018) (Spectre) (Meltdown) (Foreshadow)

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.7 121035 Security Updates for Windows 10 / Windows Server 2016 (January 2019) (Spectre)

MEDIUM 4.7 119239 Security Updates for Windows 10 / Windows Server 2016 (September 2018) (Spectre)

Deploy-01 50 HAVOC

12 43 23 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 78

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 125063 KB4499175: and R2 May 2019 Security Update (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (BlueKeep)

CRITICAL 10.0 127846 KB4512486: Windows 7 and August 2019 Security Update

CRITICAL 10.0 64784 Microsoft SQL Server Unsupported Version Detection

CRITICAL 10.0 97639 Mozilla Firefox < 52.0 Multiple Vulnerabilities

CRITICAL 10.0 102359 Mozilla Firefox < 55 Multiple Vulnerabilities

CRITICAL 10.0 103680 Mozilla Firefox < 56 Multiple Vulnerabilities

CRITICAL 10.0 104638 Mozilla Firefox < 57 Multiple Vulnerabilities

CRITICAL 10.0 106303 Mozilla Firefox < 58 Multiple Vulnerabilities

CRITICAL 10.0 109869 Mozilla Firefox < 60 Multiple Critical Vulnerabilities

CRITICAL 10.0 121512 Mozilla Firefox < 65.0

CRITICAL 10.0 126072 Mozilla Firefox < 67.0.4

CRITICAL 10.0 40362 Mozilla Foundation Unsupported Application Detection

HIGH 9.3 111689 KB4343899: Windows 7 and Windows Server 2008 R2 August 2018 Security Update (Foreshadow)

HIGH 9.3 125824 KB4503269: Windows 7 and Windows Server 2008 R2 June 2019 Security Update

HIGH 9.3 126571 KB4507456: Windows 7 and Windows Server 2008 R2 July 2019 Security Update (SWAPGS)

HIGH 9.3 128640 KB4516033: Windows 7 and Windows Server 2008 R2 September 2019 Security Update

HAVOC 51 HIGH 9.3 129718 KB4520003: Windows 7 and Windows Server 2008 R2 October 2019 Security Update

HIGH 9.3 130905 KB4525233: Windows 7 and Windows Server 2008 R2 November 2019 Security Update

HIGH 9.3 48762 MS KB2269637: Insecure Library Loading Could Allow Remote Code Execution

HIGH 9.3 53382 MS11-025: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)

HIGH 9.3 87253 MS15-124: Cumulative Security Update for Internet Explorer (3116180)

HIGH 9.3 105213 Mozilla Firefox < 57.0.2 ANGLE Graphics Library RCE

HIGH 9.3 110811 Mozilla Firefox < 61 Multiple Critical Vulnerabilities

HIGH 9.3 118397 Mozilla Firefox < 63 Multiple Vulnerabilities

HIGH 9.3 128525 Mozilla Firefox < 69.0

HIGH 9.3 103127 Windows 7 and Windows Server 2008 R2 September 2017 Security Updates

HIGH 8.3 81264 MS15-011: Vulnerability in Group Policy Could Allow Remote Code Execution (3000483)

HIGH 7.6 105552 KB4056897: Windows 7 and Windows Server 2008 R2 January 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 108290 KB4088878: Windows 7 and Windows Server 2008 R2 March 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 129166 Security Update for Internet Explorer (CVE-2019-1367)

HIGH 7.6 127852 Security Updates for Internet Explorer (August 2019)

HIGH 7.6 126582 Security Updates for Internet Explorer (July 2019)

HIGH 7.6 104892 Security Updates for Internet Explorer (June 2017)

HIGH 7.6 125828 Security Updates for Internet Explorer (June 2019)

HIGH 7.6 130912 Security Updates for Internet Explorer (November 2019)

HIGH 7.6 129728 Security Updates for Internet Explorer (October 2019)

HIGH 7.6 128647 Security Updates for Internet Explorer (September 2019)

HAVOC 52 HIGH 7.5 92755 Firefox < 48 Multiple Vulnerabilities

HIGH 7.5 117941 Mozilla Firefox < 49 Multiple Vulnerabilities

HIGH 7.5 93662 Mozilla Firefox < 49.0 Multiple Vulnerabilities

HIGH 7.5 94960 Mozilla Firefox < 50.0 Multiple Vulnerabilities

HIGH 7.5 95886 Mozilla Firefox < 50.1 Multiple Vulnerabilities

HIGH 7.5 96776 Mozilla Firefox < 51.0 Multiple Vulnerabilities

HIGH 7.5 99125 Mozilla Firefox < 52.0.1 CreateImageBitmap RCE

HIGH 7.5 99632 Mozilla Firefox < 53 Multiple Vulnerabilities

HIGH 7.5 100810 Mozilla Firefox < 54 Multiple Vulnerabilities

HIGH 7.5 108377 Mozilla Firefox < 59 Multiple Vulnerabilities

HIGH 7.5 108587 Mozilla Firefox < 59.0.1 Multiple Code Execution Vulnerabilities

HIGH 7.5 117294 Mozilla Firefox < 62 Multiple Critical Vulnerabilities

HIGH 7.5 119604 Mozilla Firefox < 64.0 Multiple Vulnerabilities

HIGH 7.5 122948 Mozilla Firefox < 66.0

HIGH 7.5 125361 Mozilla Firefox < 67.0

HIGH 7.5 126002 Mozilla Firefox < 67.0.3

HIGH 7.5 126622 Mozilla Firefox < 68.0

HIGH 7.5 108756 Mozilla Firefox ESR < 59.0.2 Denial of Service Vulnerability

MEDIUM 6.8 100127 Mozilla Firefox < 53.0.2 ANGLE Graphics Library RCE

MEDIUM 6.8 122233 Mozilla Firefox < 65.0.1

MEDIUM 6.8 123012 Mozilla Firefox < 66.0.1

MEDIUM 6.8 130170 Mozilla Firefox < 70.0 Multiple Vulnerabilities

MEDIUM 6.8 126600 Security Updates for Microsoft .NET Framework (July 2019)

MEDIUM 6.6 127910 Microsoft Defender Elevation of Privilege Vulnerability (CVE-2019-1161)

MEDIUM 6.4 117921 Mozilla Firefox < 62.0.3 Multiple Vulnerabilities

HAVOC 53 MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.8 129974 Oracle MySQL Connectors Multiple Vulnerabilities (Oct 2019 CPU)

MEDIUM 5.0 95475 Mozilla Firefox < 50.0.2 nsSMILTimeContainer.cpp SVG Animation RCE

MEDIUM 5.0 105040 Mozilla Firefox < 57.0.1 Multiple Vulnerabilities

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 4.7 105613 ADV180002: Microsoft SQL Server January 2018 Security Update (Meltdown) (Spectre)

MEDIUM 4.7 105616 Mozilla Firefox < 57.0.4 Speculative Execution Side-Channel Attack Vulnerability (Spectre)

MEDIUM 4.4 117668 Mozilla Firefox < 62.0.2 Vulnerability

MEDIUM 4.3 78447 MS KB3009008: Vulnerability in SSL 3.0 Could Allow Information Disclosure (POODLE)

MEDIUM 4.3 106561 Mozilla Firefox < 58.0.1 Arbitrary Code Execution

MEDIUM 4.3 125877 Mozilla Firefox < 67.0.2

MEDIUM 4.3 129101 Mozilla Firefox < 69.0.1

MEDIUM 4.3 129004 Oracle MySQL Connectors DoS (Jul 2018 CPU)

MEDIUM 4.3 125340 Oracle MySQL Connectors Multiple Vulnerabilities (Apr 2019 CPU)

HAVOC 54 Venom

4 12 13 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 29

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 125063 KB4499175: Windows 7 and Windows Server 2008 R2 May 2019 Security Update (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (BlueKeep)

CRITICAL 10.0 72704 Microsoft .NET Framework Unsupported

CRITICAL 10.0 64784 Microsoft SQL Server Unsupported Version Detection

CRITICAL 10.0 40362 Mozilla Foundation Unsupported Application Detection

HIGH 9.3 111689 KB4343899: Windows 7 and Windows Server 2008 R2 August 2018 Security Update (Foreshadow)

HIGH 9.3 48762 MS KB2269637: Insecure Library Loading Could Allow Remote Code Execution

HIGH 9.3 53382 MS11-025: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)

HIGH 9.3 87253 MS15-124: Cumulative Security Update for Internet Explorer (3116180)

HIGH 9.3 103127 Windows 7 and Windows Server 2008 R2 September 2017 Security Updates

HIGH 8.5 84738 MS15-058: Vulnerabilities in SQL Server Could Allow Remote Code Execution (3065718)

HIGH 8.3 81264 MS15-011: Vulnerability in Group Policy Could Allow Remote Code Execution (3000483)

HIGH 7.6 105552 KB4056897: Windows 7 and Windows Server 2008 R2 January 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 108290 KB4088878: Windows 7 and Windows Server 2008 R2 March 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 104892 Security Updates for Internet Explorer (June 2017)

HIGH 7.5 128080 VLC < 3.0.8 Multiple Vulnerabilities

Venom 55 HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.9 63155 Microsoft Windows Unquoted Service Path Enumeration

MEDIUM 6.8 109730 7-Zip < 18.05 Memory Corruption Arbitrary Code Execution

MEDIUM 6.8 130170 Mozilla Firefox < 70.0 Multiple Vulnerabilities

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.7 105613 ADV180002: Microsoft SQL Server January 2018 Security Update (Meltdown) (Spectre)

MEDIUM 4.3 78447 MS KB3009008: Vulnerability in SSL 3.0 Could Allow Information Disclosure (POODLE)

MEDIUM 4.3 77162 MS14-044: Vulnerability in SQL Server Could Allow Elevation of Privilege (2984340)

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

Venom 56 WSUS1

1 3 6 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 10

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 100760 KB4022715: Windows 10 Version 1607 and Windows Server 2016 June 2017 Cumulative Update

HIGH 9.3 106796 KB4074590: Windows 10 Version 1607 and Windows Server 2016 February 2018 Security Update (Meltdown)(Spectre)

HIGH 9.3 111685 KB4343887: Windows 10 Version 1607 and Windows Server 2016 August 2018 Security Update (Foreshadow)

HIGH 7.6 105548 KB4056890: Windows 10 Version 1607 and Windows Server 2016 January 2018 Security Update (Meltdown)(Spectre)

MEDIUM 6.8 130170 Mozilla Firefox < 70.0 Multiple Vulnerabilities

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.7 121035 Security Updates for Windows 10 / Windows Server 2016 (January 2019) (Spectre)

WSUS1 57 attacker

2 7 5 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 14

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 100760 KB4022715: Windows 10 Version 1607 and Windows Server 2016 June 2017 Cumulative Update

CRITICAL 10.0 62758 Microsoft XML Parser (MSXML) and XML Core Services Unsupported

HIGH 9.4 51873 Oracle Document Capture Multiple Vulnerabilities

HIGH 9.3 54841 Data Dynamics ActiveBar ActiveX Controls Code Execution

HIGH 9.3 106796 KB4074590: Windows 10 Version 1607 and Windows Server 2016 February 2018 Security Update (Meltdown)(Spectre)

HIGH 9.3 111685 KB4343887: Windows 10 Version 1607 and Windows Server 2016 August 2018 Security Update (Foreshadow)

HIGH 9.3 125058 KB4494440: Windows 10 Version 1607 and Windows Server 2016 May 2019 Security Update (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)

HIGH 9.3 53382 MS11-025: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)

HIGH 7.6 105548 KB4056890: Windows 10 Version 1607 and Windows Server 2016 January 2018 Security Update (Meltdown)(Spectre)

MEDIUM 6.8 130170 Mozilla Firefox < 70.0 Multiple Vulnerabilities

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

attacker 58 bearcat

4 17 16 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 37

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 125063 KB4499175: Windows 7 and Windows Server 2008 R2 May 2019 Security Update (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (BlueKeep)

CRITICAL 10.0 102082 Microsoft Access Unsupported Version Detection

CRITICAL 10.0 93229 Microsoft Visio Viewer Unsupported Version Detection

CRITICAL 10.0 62758 Microsoft XML Parser (MSXML) and XML Core Services Unsupported

HIGH 9.4 51873 Oracle Document Capture Multiple Vulnerabilities

HIGH 9.3 54841 Data Dynamics ActiveBar ActiveX Controls Code Execution

HIGH 9.3 111689 KB4343899: Windows 7 and Windows Server 2008 R2 August 2018 Security Update (Foreshadow)

HIGH 9.3 48762 MS KB2269637: Insecure Library Loading Could Allow Remote Code Execution

HIGH 9.3 53382 MS11-025: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)

HIGH 9.3 59039 MS12-031: Vulnerability in Microsoft Visio Viewer 2010 Could Allow Remote Code Execution (2597981)

HIGH 9.3 59906 MS12-043: Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (2722479)

HIGH 9.3 61535 MS12-060: Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2720573)

HIGH 9.3 87253 MS15-124: Cumulative Security Update for Internet Explorer (3116180)

HIGH 9.3 27525 Microsoft Office Service Pack Out of Date

HIGH 9.3 103127 Windows 7 and Windows Server 2008 R2 September 2017 Security Updates

bearcat 59 HIGH 8.3 81264 MS15-011: Vulnerability in Group Policy Could Allow Remote Code Execution (3000483)

HIGH 7.6 105552 KB4056897: Windows 7 and Windows Server 2008 R2 January 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 108290 KB4088878: Windows 7 and Windows Server 2008 R2 March 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 104892 Security Updates for Internet Explorer (June 2017)

HIGH 7.5 128080 VLC < 3.0.8 Multiple Vulnerabilities

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.8 109730 7-Zip < 18.05 Memory Corruption Arbitrary Code Execution

MEDIUM 6.8 59913 MS12-050: Vulnerabilities in SharePoint Could Allow Elevation of Privilege (2695502)

MEDIUM 6.8 126600 Security Updates for Microsoft .NET Framework (July 2019)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.8 56177 MS11-074: Vulnerabilities in Microsoft SharePoint Could Allow Elevation of Privilege (2451858)

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 5.0 95657 VMware vSphere Client XXE Injection Information Disclosure (VMSA-2016-0022)

MEDIUM 4.3 78447 MS KB3009008: Vulnerability in SSL 3.0 Could Allow Information Disclosure (POODLE)

MEDIUM 4.3 65882 MS13-035: Vulnerability in HTML Sanitization Component Could Allow Elevation of Privilege (2821818)

MEDIUM 4.3 71321 MS13-106: Vulnerability in a Microsoft Office Shared Component Could Allow Security Feature Bypass (2905238)

bearcat 60 MEDIUM 4.3 58453 Terminal Services Doesn't Use Network Level Authentication (NLA) Only

MEDIUM 4.0 73992 MS KB2960358: Update for Disabling RC4 in .NET TLS

bearcat 61 beaumont.tc.stlukes-hospice.org.uk

0 2 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 4

SEVERITY CVSS PLUGIN NAME

HIGH 7.2 118885 ESXi 6.0 / 6.5 / 6.7 Multiple Vulnerabilities (VMSA-2018-0027) (Remote Check)

HIGH 7.2 123518 ESXi 6.0 / 6.5 / 6.7 Multiple Vulnerabilities (VMSA-2019-0005) (Remote Check)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

beaumont.tc.stlukes-hospice.org.uk 62 beaumontipmi.tc.stlukes-hospice.org.uk

1 2 6 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 9

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 93650 Dropbear SSH Server < 2016.72 Multiple Vulnerabilities

HIGH 7.8 80101 IPMI v2.0 Password Hash Disclosure

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.8 42880 SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection

MEDIUM 5.8 71533 SuperMicro Device Uses Default SSH Host Key

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

beaumontipmi.tc.stlukes-hospice.org.uk 63 besx1.tc.stlukes-hospice.org.uk

0 2 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 4

SEVERITY CVSS PLUGIN NAME

HIGH 7.2 118885 ESXi 6.0 / 6.5 / 6.7 Multiple Vulnerabilities (VMSA-2018-0027) (Remote Check)

HIGH 7.2 123518 ESXi 6.0 / 6.5 / 6.7 Multiple Vulnerabilities (VMSA-2019-0005) (Remote Check)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

besx1.tc.stlukes-hospice.org.uk 64 besx2.tc.stlukes-hospice.org.uk

0 3 3 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 6

SEVERITY CVSS PLUGIN NAME

HIGH 7.2 118885 ESXi 6.0 / 6.5 / 6.7 Multiple Vulnerabilities (VMSA-2018-0027) (Remote Check)

HIGH 7.2 123518 ESXi 6.0 / 6.5 / 6.7 Multiple Vulnerabilities (VMSA-2019-0005) (Remote Check)

HIGH 7.2 118466 ESXi 6.0 / 6.5 / 6.7 Out-of-Bounds Read Vulnerability (VMSA-2018-0026) (Remote Check)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 4.7 111759 ESXi 5.5 / 6.0 / 6.5 / 6.7 Side Channel Vulnerability (Foreshadow) (VMSA-2018-0020) (remote check)

besx2.tc.stlukes-hospice.org.uk 65 blackbird.tc.stlukes-hospice.org.uk

3 11 13 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 27

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 125063 KB4499175: Windows 7 and Windows Server 2008 R2 May 2019 Security Update (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (BlueKeep)

CRITICAL 10.0 64784 Microsoft SQL Server Unsupported Version Detection

CRITICAL 10.0 40362 Mozilla Foundation Unsupported Application Detection

HIGH 9.3 111689 KB4343899: Windows 7 and Windows Server 2008 R2 August 2018 Security Update (Foreshadow)

HIGH 9.3 48762 MS KB2269637: Insecure Library Loading Could Allow Remote Code Execution

HIGH 9.3 53382 MS11-025: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)

HIGH 9.3 87253 MS15-124: Cumulative Security Update for Internet Explorer (3116180)

HIGH 9.3 103127 Windows 7 and Windows Server 2008 R2 September 2017 Security Updates

HIGH 8.5 84738 MS15-058: Vulnerabilities in SQL Server Could Allow Remote Code Execution (3065718)

HIGH 8.3 81264 MS15-011: Vulnerability in Group Policy Could Allow Remote Code Execution (3000483)

HIGH 7.6 105552 KB4056897: Windows 7 and Windows Server 2008 R2 January 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 108290 KB4088878: Windows 7 and Windows Server 2008 R2 March 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 104892 Security Updates for Internet Explorer (June 2017)

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.8 130170 Mozilla Firefox < 70.0 Multiple Vulnerabilities blackbird.tc.stlukes-hospice.org.uk 66 MEDIUM 6.8 126600 Security Updates for Microsoft .NET Framework (July 2019)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.7 105613 ADV180002: Microsoft SQL Server January 2018 Security Update (Meltdown) (Spectre)

MEDIUM 4.3 78447 MS KB3009008: Vulnerability in SSL 3.0 Could Allow Information Disclosure (POODLE)

MEDIUM 4.3 77162 MS14-044: Vulnerability in SQL Server Could Allow Elevation of Privilege (2984340)

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

MEDIUM 4.0 73992 MS KB2960358: Update for Disabling RC4 in .NET TLS

blackbird.tc.stlukes-hospice.org.uk 67 blvault1.tc.stlukes-hospice.org.uk

0 0 4 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 4

SEVERITY CVSS PLUGIN NAME

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

blvault1.tc.stlukes-hospice.org.uk 68 buccaneer.tc.stlukes-hospice.org.uk

0 3 13 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 16

SEVERITY CVSS PLUGIN NAME

HIGH 7.5 26925 VNC Server Unauthenticated Access

HIGH 7.5 66174 VNC Server Unauthenticated Access: Screenshot

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 97861 Network Time Protocol (NTP) Mode 6 Scanner

MEDIUM 5.0 10988 Novell NetWare ncp Service NDS Object Enumeration

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

MEDIUM 4.3 66848 SSL Null Cipher Suites Supported

MEDIUM 4.3 26928 SSL Weak Cipher Suites Supported

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

MEDIUM 4.3 10891 X Display Manager Control Protocol (XDMCP) Detection

buccaneer.tc.stlukes-hospice.org.uk 69 camm.tc.stlukes-hospice.org.uk

0 3 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 5

SEVERITY CVSS PLUGIN NAME

HIGH 7.2 118885 ESXi 6.0 / 6.5 / 6.7 Multiple Vulnerabilities (VMSA-2018-0027) (Remote Check)

HIGH 7.2 123518 ESXi 6.0 / 6.5 / 6.7 Multiple Vulnerabilities (VMSA-2019-0005) (Remote Check)

HIGH 7.2 118466 ESXi 6.0 / 6.5 / 6.7 Out-of-Bounds Read Vulnerability (VMSA-2018-0026) (Remote Check)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 4.7 111759 ESXi 5.5 / 6.0 / 6.5 / 6.7 Speculative Execution Side Channel Vulnerability (Foreshadow) (VMSA-2018-0020) (remote check)

camm.tc.stlukes-hospice.org.uk 70 catalina.tc.stlukes-hospice.org.uk

12 27 19 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 58

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 72704 Microsoft .NET Framework Unsupported

CRITICAL 10.0 102082 Microsoft Access Unsupported Version Detection

CRITICAL 10.0 97994 Microsoft IIS 6.0 Unsupported Version Detection

CRITICAL 10.0 22024 Microsoft Internet Explorer Unsupported Version Detection

CRITICAL 10.0 93227 Microsoft Office Compatibility Pack Unsupported Version Detection

CRITICAL 10.0 56998 Microsoft Office Unsupported Version Detection

CRITICAL 10.0 93228 Microsoft PowerPoint Viewer Unsupported Version Detection

CRITICAL 10.0 100791 Microsoft Security Advisory 4025685: Guidance for older platforms (XP / 2003) (EXPLODINGCAN)

CRITICAL 10.0 84729 Microsoft Unsupported Installation Detection

CRITICAL 10.0 62758 Microsoft XML Parser (MSXML) and XML Core Services Unsupported

CRITICAL 10.0 40362 Mozilla Foundation Unsupported Application Detection

CRITICAL 10.0 108797 Unsupported Windows OS (remote)

HIGH 9.3 48762 MS KB2269637: Insecure Library Loading Could Allow Remote Code Execution

HIGH 9.3 33107 MS08-011: Vulnerabilities in Microsoft Works File Converter Could Allow Remote Code Execution (947081)

HIGH 9.3 31047 MS08-013: Vulnerability in Microsoft Office Could Allow Remote Code Execution (947108)

HIGH 9.3 33870 MS08-041: Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Access Could Allow Remote Code Execution (955617)

catalina.tc.stlukes-hospice.org.uk 71 HIGH 9.3 39783 MS09-043: Vulnerabilities in Microsoft Office Web Components Control Could Allow Remote Code Execution (973472)

HIGH 9.3 40562 MS09-043: Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (957638)

HIGH 9.3 47712 MS10-044: Vulnerabilities in Microsoft Office Access ActiveX Controls Could Allow Remote Code Execution (982335)

HIGH 9.3 51177 MS10-105: Vulnerabilities in Microsoft Office Graphics Filters Could Allow for Remote Code Execution (968095)

HIGH 9.3 53382 MS11-025: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)

HIGH 9.3 59906 MS12-043: Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (2722479)

HIGH 9.3 61535 MS12-060: Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2720573)

HIGH 9.3 63420 MS13-002: Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (2756145)

HIGH 9.3 89752 MS16-029: Security Update for Microsoft Office to Address Remote Code Execution (3141806)

HIGH 9.3 27525 Microsoft Office Service Pack Out of Date

HIGH 9.3 100464 Microsoft Windows SMBv1 Multiple Vulnerabilities

HIGH 9.3 101371 Security Update for Microsoft Office Products (July 2017)

HIGH 9.3 100782 Security Update for Microsoft Office Products (June 2017)

HIGH 9.3 100103 Security Update for Microsoft Office Products (May 2017)

HIGH 9.3 103751 Security Updates for Microsoft Office Compatibility Pack SP3 (October 2017)

HIGH 9.3 108973 Security Updates for Microsoft Office Compatibility Products (April 2018)

HIGH 9.3 109615 Security Updates for Microsoft Office Compatibility Products (May 2018)

HIGH 9.3 111698 Security Updates for Microsoft Office Viewer Products / Office Compatibility Products (August 2018)

HIGH 8.3 81264 MS15-011: Vulnerability in Group Policy Could Allow Remote Code Execution (3000483)

catalina.tc.stlukes-hospice.org.uk 72 HIGH 7.5 22190 MS06-048: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (922968)

HIGH 7.5 21564 VNC Security Type Enforcement Failure Remote Authentication Bypass

HIGH 7.2 69557 Novell Client / Client 2 Multiple Vulnerabilities

HIGH 6.9 59909 MS12-046: Vulnerability in Visual Basic for Applications Could Allow Remote Code Execution (2707960)

MEDIUM 6.9 84742 MS KB3074162: Vulnerability in Microsoft Malicious Software Removal Tool Could Allow Elevation of Privilege

MEDIUM 6.9 83355 MS15-050: Vulnerability in Service Control Manager Could Allow Elevation of Privilege (3055642)

MEDIUM 6.8 109730 7-Zip < 18.05 Memory Corruption Arbitrary Code Execution

MEDIUM 6.8 48761 MS KB982316: Elevation of Privilege Using Windows Service Isolation Bypass

MEDIUM 6.8 63478 Microsoft Windows LM / NTLMv1 Authentication Enabled

MEDIUM 6.8 103876 Microsoft Windows SMB Server (2017-10) Multiple Vulnerabilities (uncredentialed check)

MEDIUM 6.8 130170 Mozilla Firefox < 70.0 Multiple Vulnerabilities

MEDIUM 6.1 80494 MS15-005: Vulnerability in Network Location Awareness Service Could Allow Security Feature Bypass (3022777)

MEDIUM 5.8 87252 MS KB3123040: Improperly Issued Digital Certificates Could Allow Spoofing

MEDIUM 5.8 90510 MS16-047: Security Update for SAM and LSAD Remote Protocols (3148527) (Badlock) (uncredentialed check)

MEDIUM 5.1 22033 MS06-039: Vulnerabilities in Microsoft Office Filters Could Allow Remote Code Execution (915384)

MEDIUM 5.1 18405 Microsoft Windows Server Man-in-the-Middle Weakness

MEDIUM 5.0 26920 Microsoft Windows SMB NULL Session Authentication

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 4.3 78447 MS KB3009008: Vulnerability in SSL 3.0 Could Allow Information Disclosure (POODLE)

catalina.tc.stlukes-hospice.org.uk 73 MEDIUM 4.3 110496 Security Updates for Microsoft Office Compatibility Products (June 2018)

MEDIUM 4.3 117424 Security Updates for Microsoft Office Compatibility Products (September 2018)

MEDIUM 4.3 122317 Security Updates for Microsoft Office Viewers And Compatibility Products (February 2019)

MEDIUM 4.3 57690 Terminal Services Encryption Level is Medium or Low

catalina.tc.stlukes-hospice.org.uk 74 dakota.tc.stlukes-hospice.org.uk

38 42 43 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 123

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 77712 Adobe Reader < 10.1.12 / 11.0.09 Multiple Vulnerabilities (APSB14-20)

CRITICAL 10.0 79856 Adobe Reader < 10.1.13 / 11.0.10 Multiple Vulnerabilities (APSB14-28)

CRITICAL 10.0 83471 Adobe Reader < 10.1.14 / 11.0.11 Multiple Vulnerabilities (APSB15-10)

CRITICAL 10.0 84801 Adobe Reader < 10.1.15 / 11.0.12 / 2015.006.30060 / 2015.008.20082 Multiple Vulnerabilities (APSB15-15)

CRITICAL 10.0 87918 Adobe Reader < 11.0.14 / 15.006.30119 / 15.010.20056 Multiple Vulnerabilities (APSB16-02)

CRITICAL 10.0 89831 Adobe Reader < 11.0.15 / 15.006.30121 / 15.010.20060 Multiple Vulnerabilities (APSB16-09)

CRITICAL 10.0 91097 Adobe Reader < 11.0.16 / 15.006.30172 / 15.016.20039 Multiple Vulnerabilities (APSB16-14)

CRITICAL 10.0 92035 Adobe Reader < 11.0.17 / 15.006.30198 / 15.017.20050 Multiple Vulnerabilities (APSB16-26)

CRITICAL 10.0 94072 Adobe Reader < 11.0.18 / 15.006.30243 / 15.020.20039 Multiple Vulnerabilities (APSB16-33)

CRITICAL 10.0 96453 Adobe Reader < 11.0.19 / 15.006.30279 / 15.023.20053 Multiple Vulnerabilities (APSB17-01)

CRITICAL 10.0 99374 Adobe Reader < 11.0.20 / 2015.006.30306 / 2017.009.20044 Multiple Vulnerabilities (APSB17-11)

CRITICAL 10.0 102428 Adobe Reader < 11.0.21 / 2015.006.30355 / 2017.011.30066 / 2017.012.20098 Multiple Vulnerabilities (APSB17-24)

CRITICAL 10.0 104627 Adobe Reader < 11.0.23 / 2015.006.30392 / 2017.011.30068 / 2018.009.20044 Multiple Vulnerabilities (APSB17-36)

CRITICAL 10.0 86403 Adobe Reader <= 10.1.15 / 11.0.12 / 2015.006.30060 / 2015.008.20082 Multiple Vulnerabilities (APSB15-24) dakota.tc.stlukes-hospice.org.uk 75 CRITICAL 10.0 56213 Adobe Reader Unsupported Version Detection

CRITICAL 10.0 83439 Firefox < 38.0 Multiple Vulnerabilities

CRITICAL 10.0 84581 Firefox < 39.0 Multiple Vulnerabilities (Logjam)

CRITICAL 10.0 85386 Firefox < 40 Multiple Vulnerabilities

CRITICAL 10.0 85689 Firefox < 40.0.3 Multiple Vulnerabilities

CRITICAL 10.0 87476 Firefox < 43 Multiple Vulnerabilities

CRITICAL 10.0 88461 Firefox < 44 Multiple Vulnerabilities

CRITICAL 10.0 89875 Firefox < 45 Multiple Vulnerabilities

CRITICAL 10.0 90793 Firefox < 46 Multiple Vulnerabilities

CRITICAL 10.0 22024 Microsoft Internet Explorer Unsupported Version Detection

CRITICAL 10.0 64784 Microsoft SQL Server Unsupported Version Detection

CRITICAL 10.0 100791 Microsoft Security Advisory 4025685: Guidance for older platforms (XP / 2003) (EXPLODINGCAN)

CRITICAL 10.0 84729 Microsoft Windows Server 2003 Unsupported Installation Detection

CRITICAL 10.0 62758 Microsoft XML Parser (MSXML) and XML Core Services Unsupported

CRITICAL 10.0 97639 Mozilla Firefox < 52.0 Multiple Vulnerabilities

CRITICAL 10.0 102359 Mozilla Firefox < 55 Multiple Vulnerabilities

CRITICAL 10.0 103680 Mozilla Firefox < 56 Multiple Vulnerabilities

CRITICAL 10.0 104638 Mozilla Firefox < 57 Multiple Vulnerabilities

CRITICAL 10.0 106303 Mozilla Firefox < 58 Multiple Vulnerabilities

CRITICAL 10.0 109869 Mozilla Firefox < 60 Multiple Critical Vulnerabilities

CRITICAL 10.0 121512 Mozilla Firefox < 65.0

CRITICAL 10.0 126072 Mozilla Firefox < 67.0.4

CRITICAL 10.0 40362 Mozilla Foundation Unsupported Application Detection

CRITICAL 10.0 108797 Unsupported Windows OS (remote)

HIGH 9.4 51873 Oracle Document Capture Multiple Vulnerabilities dakota.tc.stlukes-hospice.org.uk 76 HIGH 9.3 91230 7-Zip < 16.00 Multiple Vulnerabilities

HIGH 9.3 96907 Cisco WebEx for Firefox RCE (cisco-sa-20170124-webex)

HIGH 9.3 54841 Data Dynamics ActiveBar ActiveX Controls Code Execution

HIGH 9.3 22312 DynaZip < 5.0.0.8 / 6.0.0.5 Zip Archive Handling Multiple Overflows

HIGH 9.3 86071 Firefox < 41 Multiple Vulnerabilities

HIGH 9.3 91547 Firefox < 47 Multiple Vulnerabilities

HIGH 9.3 48762 MS KB2269637: Insecure Library Loading Could Allow Remote Code Execution

HIGH 9.3 39783 MS09-043: Vulnerabilities in Microsoft Office Web Components Control Could Allow Remote Code Execution (973472)

HIGH 9.3 40562 MS09-043: Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (957638)

HIGH 9.3 42118 MS09-062: Vulnerabilities in GDI+ Could Allow Remote Code Execution (957488)

HIGH 9.3 53382 MS11-025: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)

HIGH 9.3 61535 MS12-060: Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2720573)

HIGH 9.3 100464 Microsoft Windows SMBv1 Multiple Vulnerabilities

HIGH 9.3 105213 Mozilla Firefox < 57.0.2 ANGLE Graphics Library RCE

HIGH 9.3 110811 Mozilla Firefox < 61 Multiple Critical Vulnerabilities

HIGH 9.3 118397 Mozilla Firefox < 63 Multiple Vulnerabilities

HIGH 9.3 128525 Mozilla Firefox < 69.0

HIGH 9.3 100782 Security Update for Microsoft Office Products (June 2017)

HIGH 8.3 81264 MS15-011: Vulnerability in Group Policy Could Allow Remote Code Execution (3000483)

HIGH 7.5 86764 Firefox < 42 Multiple Vulnerabilities

HIGH 7.5 92755 Firefox < 48 Multiple Vulnerabilities

dakota.tc.stlukes-hospice.org.uk 77 HIGH 7.5 117941 Mozilla Firefox < 49 Multiple Vulnerabilities

HIGH 7.5 93662 Mozilla Firefox < 49.0 Multiple Vulnerabilities

HIGH 7.5 94960 Mozilla Firefox < 50.0 Multiple Vulnerabilities

HIGH 7.5 95886 Mozilla Firefox < 50.1 Multiple Vulnerabilities

HIGH 7.5 96776 Mozilla Firefox < 51.0 Multiple Vulnerabilities

HIGH 7.5 99125 Mozilla Firefox < 52.0.1 CreateImageBitmap RCE

HIGH 7.5 99632 Mozilla Firefox < 53 Multiple Vulnerabilities

HIGH 7.5 100810 Mozilla Firefox < 54 Multiple Vulnerabilities

HIGH 7.5 108377 Mozilla Firefox < 59 Multiple Vulnerabilities

HIGH 7.5 108587 Mozilla Firefox < 59.0.1 Multiple Code Execution Vulnerabilities

HIGH 7.5 117294 Mozilla Firefox < 62 Multiple Critical Vulnerabilities

HIGH 7.5 119604 Mozilla Firefox < 64.0 Multiple Vulnerabilities

HIGH 7.5 122948 Mozilla Firefox < 66.0

HIGH 7.5 125361 Mozilla Firefox < 67.0

HIGH 7.5 126002 Mozilla Firefox < 67.0.3

HIGH 7.5 126622 Mozilla Firefox < 68.0

HIGH 7.5 108756 Mozilla Firefox ESR < 59.0.2 Denial of Service Vulnerability

HIGH 7.5 21564 VNC Security Type Enforcement Failure Remote Authentication Bypass

HIGH 7.2 69557 Novell Client / Client 2 Multiple Vulnerabilities

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.9 84742 MS KB3074162: Vulnerability in Microsoft Malicious Software Removal Tool Could Allow Elevation of Privilege

MEDIUM 6.9 83355 MS15-050: Vulnerability in Service Control Manager Could Allow Elevation of Privilege (3055642)

MEDIUM 6.8 109800 7-Zip < 18.00 Multiple Vulnerabilities

MEDIUM 6.8 109730 7-Zip < 18.05 Memory Corruption Arbitrary Code Execution

dakota.tc.stlukes-hospice.org.uk 78 MEDIUM 6.8 69476 FileZilla Client < 3.7.2 SFTP Integer Overflow

MEDIUM 6.8 69494 FileZilla Client < 3.7.3 Multiple Vulnerabilities

MEDIUM 6.8 82998 Firefox < 37.0.2 Failed Plugin Memory Corruption

MEDIUM 6.8 86418 Firefox < 41.0.2 'fetch' API Cross-Origin Bypass

MEDIUM 6.8 88754 Firefox < 44.0.2 Service Workers Security Bypass

MEDIUM 6.8 48761 MS KB982316: Elevation of Privilege Using Windows Service Isolation Bypass

MEDIUM 6.8 63478 Microsoft Windows LM / NTLMv1 Authentication Enabled

MEDIUM 6.8 103876 Microsoft Windows SMB Server (2017-10) Multiple Vulnerabilities (uncredentialed check)

MEDIUM 6.8 100127 Mozilla Firefox < 53.0.2 ANGLE Graphics Library RCE

MEDIUM 6.8 122233 Mozilla Firefox < 65.0.1

MEDIUM 6.8 123012 Mozilla Firefox < 66.0.1

MEDIUM 6.8 130170 Mozilla Firefox < 70.0 Multiple Vulnerabilities

MEDIUM 6.4 117921 Mozilla Firefox < 62.0.3 Multiple Vulnerabilities

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 6.1 80494 MS15-005: Vulnerability in Network Location Awareness Service Could Allow Security Feature Bypass (3022777)

MEDIUM 5.8 87252 MS KB3123040: Improperly Issued Digital Certificates Could Allow Spoofing

MEDIUM 5.8 90510 MS16-047: Security Update for SAM and LSAD Remote Protocols (3148527) (Badlock) (uncredentialed check)

MEDIUM 5.1 18405 Microsoft Windows Remote Desktop Protocol Server Man-in-the-Middle Weakness

MEDIUM 5.0 109799 7-Zip < 16.03 NULL Pointer Dereference DoS

MEDIUM 5.0 26920 Microsoft Windows SMB NULL Session Authentication

MEDIUM 5.0 95475 Mozilla Firefox < 50.0.2 nsSMILTimeContainer.cpp SVG Animation RCE

dakota.tc.stlukes-hospice.org.uk 79 MEDIUM 5.0 105040 Mozilla Firefox < 57.0.1 Multiple Vulnerabilities

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.7 105616 Mozilla Firefox < 57.0.4 Speculative Execution Side-Channel Attack Vulnerability (Spectre)

MEDIUM 4.4 117668 Mozilla Firefox < 62.0.2 Vulnerability

MEDIUM 4.3 85275 Firefox < 39.0.3 PDF Reader Arbitrary File Access

MEDIUM 4.3 78447 MS KB3009008: Vulnerability in SSL 3.0 Could Allow Information Disclosure (POODLE)

MEDIUM 4.3 55129 MS11-049: Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure (2543893)

MEDIUM 4.3 106561 Mozilla Firefox < 58.0.1 Arbitrary Code Execution

MEDIUM 4.3 125877 Mozilla Firefox < 67.0.2

MEDIUM 4.3 129101 Mozilla Firefox < 69.0.1

MEDIUM 4.3 26928 SSL Weak Cipher Suites Supported

MEDIUM 4.3 81606 SSL/TLS EXPORT_RSA <= 512-bit Cipher Suites Supported (FREAK)

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

MEDIUM 4.3 57690 Terminal Services Encryption Level is Medium or Low

dakota.tc.stlukes-hospice.org.uk 80 eras1.tc.stlukes-hospice.org.uk

0 0 4 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 4

SEVERITY CVSS PLUGIN NAME

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 11213 HTTP TRACE / TRACK Methods Allowed

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

eras1.tc.stlukes-hospice.org.uk 81 esx1.tc.stlukes-hospice.org.uk

0 3 3 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 6

SEVERITY CVSS PLUGIN NAME

HIGH 7.2 118885 ESXi 6.0 / 6.5 / 6.7 Multiple Vulnerabilities (VMSA-2018-0027) (Remote Check)

HIGH 7.2 123518 ESXi 6.0 / 6.5 / 6.7 Multiple Vulnerabilities (VMSA-2019-0005) (Remote Check)

HIGH 7.2 118466 ESXi 6.0 / 6.5 / 6.7 Out-of-Bounds Read Vulnerability (VMSA-2018-0026) (Remote Check)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 4.7 111759 ESXi 5.5 / 6.0 / 6.5 / 6.7 Speculative Execution Side Channel Vulnerability (Foreshadow) (VMSA-2018-0020) (remote check)

esx1.tc.stlukes-hospice.org.uk 82 esx2.tc.stlukes-hospice.org.uk

0 2 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 4

SEVERITY CVSS PLUGIN NAME

HIGH 7.2 118885 ESXi 6.0 / 6.5 / 6.7 Multiple Vulnerabilities (VMSA-2018-0027) (Remote Check)

HIGH 7.2 123518 ESXi 6.0 / 6.5 / 6.7 Multiple Vulnerabilities (VMSA-2019-0005) (Remote Check)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

esx2.tc.stlukes-hospice.org.uk 83 esx3.tc.stlukes-hospice.org.uk

0 1 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 3

SEVERITY CVSS PLUGIN NAME

HIGH 7.2 123518 ESXi 6.0 / 6.5 / 6.7 Multiple Vulnerabilities (VMSA-2019-0005) (Remote Check)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

esx3.tc.stlukes-hospice.org.uk 84 galaxy.tc.stlukes-hospice.org.uk

0 0 5 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 5

SEVERITY CVSS PLUGIN NAME

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 12217 DNS Server Cache Snooping Remote Information Disclosure

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

galaxy.tc.stlukes-hospice.org.uk 85 harrier.tc.stlukes-hospice.org.uk

0 3 12 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 15

SEVERITY CVSS PLUGIN NAME

HIGH 7.5 26925 VNC Server Unauthenticated Access

HIGH 7.5 66174 VNC Server Unauthenticated Access: Screenshot

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 97861 Network Time Protocol (NTP) Mode 6 Scanner

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

MEDIUM 4.3 66848 SSL Null Cipher Suites Supported

MEDIUM 4.3 26928 SSL Weak Cipher Suites Supported

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

MEDIUM 4.3 10891 X Display Manager Control Protocol (XDMCP) Detection

harrier.tc.stlukes-hospice.org.uk 86 hart

2 5 5 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 12

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 100760 KB4022715: Windows 10 Version 1607 and Windows Server 2016 June 2017 Cumulative Update

CRITICAL 10.0 101366 KB4025339: Windows 10 Version 1607 and Windows Server 2016 July 2017 Cumulative Update

HIGH 9.3 106796 KB4074590: Windows 10 Version 1607 and Windows Server 2016 February 2018 Security Update (Meltdown)(Spectre)

HIGH 9.3 111685 KB4343887: Windows 10 Version 1607 and Windows Server 2016 August 2018 Security Update (Foreshadow)

HIGH 9.3 125058 KB4494440: Windows 10 Version 1607 and Windows Server 2016 May 2019 Security Update (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)

HIGH 9.3 53382 MS11-025: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)

HIGH 7.6 105548 KB4056890: Windows 10 Version 1607 and Windows Server 2016 January 2018 Security Update (Meltdown)(Spectre)

MEDIUM 6.8 63478 Microsoft Windows LM / NTLMv1 Authentication Enabled

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 12217 DNS Server Cache Snooping Remote Information Disclosure

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

hart 87 hunter.tc.stlukes-hospice.org.uk

0 1 11 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 12

SEVERITY CVSS PLUGIN NAME

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 97861 Network Time Protocol (NTP) Mode 6 Scanner

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

MEDIUM 4.3 66848 SSL Null Cipher Suites Supported

MEDIUM 4.3 26928 SSL Weak Cipher Suites Supported

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

hunter.tc.stlukes-hospice.org.uk 88 hurricane.tc.stlukes-hospice.org.uk

2 3 3 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 8

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 78555 OpenSSL Unsupported

CRITICAL 10.0 58987 PHP Unsupported Version Detection

HIGH 7.5 101787 Apache 2.2.x < 2.2.34 Multiple Vulnerabilities

HIGH 7.5 77285 PHP 5.3.x < 5.3.29 Multiple Vulnerabilities

HIGH 7.5 34460 Unsupported Web Server Detection

MEDIUM 5.0 87219 OpenSSL 0.9.8 < 0.9.8zh X509_ATTRIBUTE Memory Leak DoS

MEDIUM 4.3 88098 Apache Server ETag Header Information Disclosure

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

hurricane.tc.stlukes-hospice.org.uk 89 jaguar

2 12 13 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 27

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 125063 KB4499175: Windows 7 and Windows Server 2008 R2 May 2019 Security Update (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (BlueKeep)

CRITICAL 10.0 64784 Microsoft SQL Server Unsupported Version Detection

HIGH 9.3 111689 KB4343899: Windows 7 and Windows Server 2008 R2 August 2018 Security Update (Foreshadow)

HIGH 9.3 48762 MS KB2269637: Insecure Library Loading Could Allow Remote Code Execution

HIGH 9.3 53382 MS11-025: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)

HIGH 9.3 61535 MS12-060: Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2720573)

HIGH 9.3 87253 MS15-124: Cumulative Security Update for Internet Explorer (3116180)

HIGH 9.3 103127 Windows 7 and Windows Server 2008 R2 September 2017 Security Updates

HIGH 8.5 84738 MS15-058: Vulnerabilities in SQL Server Could Allow Remote Code Execution (3065718)

HIGH 8.3 81264 MS15-011: Vulnerability in Group Policy Could Allow Remote Code Execution (3000483)

HIGH 7.6 105552 KB4056897: Windows 7 and Windows Server 2008 R2 January 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 108290 KB4088878: Windows 7 and Windows Server 2008 R2 March 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 104892 Security Updates for Internet Explorer (June 2017)

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

jaguar 90 MEDIUM 6.9 58333 MS12-021: Vulnerability in Visual Studio Could Allow Elevation of Privilege (2651019)

MEDIUM 6.8 109730 7-Zip < 18.05 Memory Corruption Arbitrary Code Execution

MEDIUM 6.8 130170 Mozilla Firefox < 70.0 Multiple Vulnerabilities

MEDIUM 6.8 126600 Security Updates for Microsoft .NET Framework (July 2019)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.7 105613 ADV180002: Microsoft SQL Server January 2018 Security Update (Meltdown) (Spectre)

MEDIUM 4.3 78447 MS KB3009008: Vulnerability in SSL 3.0 Could Allow Information Disclosure (POODLE)

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

jaguar 91 jaguar-test

3 11 10 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 24

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 125063 KB4499175: Windows 7 and Windows Server 2008 R2 May 2019 Security Update (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (BlueKeep)

CRITICAL 10.0 64784 Microsoft SQL Server Unsupported Version Detection

CRITICAL 10.0 40362 Mozilla Foundation Unsupported Application Detection

HIGH 9.3 111689 KB4343899: Windows 7 and Windows Server 2008 R2 August 2018 Security Update (Foreshadow)

HIGH 9.3 48762 MS KB2269637: Insecure Library Loading Could Allow Remote Code Execution

HIGH 9.3 53382 MS11-025: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)

HIGH 9.3 61535 MS12-060: Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2720573)

HIGH 9.3 87253 MS15-124: Cumulative Security Update for Internet Explorer (3116180)

HIGH 9.3 103127 Windows 7 and Windows Server 2008 R2 September 2017 Security Updates

HIGH 8.5 84738 MS15-058: Vulnerabilities in SQL Server Could Allow Remote Code Execution (3065718)

HIGH 8.3 81264 MS15-011: Vulnerability in Group Policy Could Allow Remote Code Execution (3000483)

HIGH 7.6 105552 KB4056897: Windows 7 and Windows Server 2008 R2 January 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 108290 KB4088878: Windows 7 and Windows Server 2008 R2 March 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 104892 Security Updates for Internet Explorer (June 2017)

jaguar-test 92 MEDIUM 6.9 58333 MS12-021: Vulnerability in Visual Studio Could Allow Elevation of Privilege (2651019)

MEDIUM 6.8 130170 Mozilla Firefox < 70.0 Multiple Vulnerabilities

MEDIUM 6.8 126600 Security Updates for Microsoft .NET Framework (July 2019)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.7 105613 ADV180002: Microsoft SQL Server January 2018 Security Update (Meltdown) (Spectre)

MEDIUM 4.3 78447 MS KB3009008: Vulnerability in SSL 3.0 Could Allow Information Disclosure (POODLE)

jaguar-test 93 liberator.tc.stlukes-hospice.org.uk

0 1 12 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 13

SEVERITY CVSS PLUGIN NAME

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 97861 Network Time Protocol (NTP) Mode 6 Scanner

MEDIUM 5.0 10988 Novell NetWare ncp Service NDS Object Enumeration

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

MEDIUM 4.3 66848 SSL Null Cipher Suites Supported

MEDIUM 4.3 26928 SSL Weak Cipher Suites Supported

MEDIUM 4.3 81606 SSL/TLS EXPORT_RSA <= 512-bit Cipher Suites Supported (FREAK)

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

liberator.tc.stlukes-hospice.org.uk 94 lightning.tc.stlukes-hospice.org.uk

3 10 14 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 27

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 100760 KB4022715: Windows 10 Version 1607 and Windows Server 2016 June 2017 Cumulative Update

CRITICAL 10.0 62758 Microsoft XML Parser (MSXML) and XML Core Services Unsupported

CRITICAL 10.0 126072 Mozilla Firefox < 67.0.4

HIGH 9.4 51873 Oracle Document Capture Multiple Vulnerabilities

HIGH 9.3 26185 EasyMail SMTP Object ActiveX Control Multiple Buffer Overflows

HIGH 9.3 106796 KB4074590: Windows 10 Version 1607 and Windows Server 2016 February 2018 Security Update (Meltdown)(Spectre)

HIGH 9.3 111685 KB4343887: Windows 10 Version 1607 and Windows Server 2016 August 2018 Security Update (Foreshadow)

HIGH 9.3 128525 Mozilla Firefox < 69.0

HIGH 7.6 105548 KB4056890: Windows 10 Version 1607 and Windows Server 2016 January 2018 Security Update (Meltdown)(Spectre)

HIGH 7.5 125361 Mozilla Firefox < 67.0

HIGH 7.5 126002 Mozilla Firefox < 67.0.3

HIGH 7.5 126622 Mozilla Firefox < 68.0

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.8 130170 Mozilla Firefox < 70.0 Multiple Vulnerabilities

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.4 112116 Security Updates for Windows 10 / Windows Server 2016 (August 2018) (Spectre) (Meltdown) (Foreshadow)

lightning.tc.stlukes-hospice.org.uk 95 MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.7 105613 ADV180002: Microsoft SQL Server January 2018 Security Update (Meltdown) (Spectre)

MEDIUM 4.7 121035 Security Updates for Windows 10 / Windows Server 2016 (January 2019) (Spectre)

MEDIUM 4.7 119239 Security Updates for Windows 10 / Windows Server 2016 (September 2018) (Spectre)

MEDIUM 4.3 125877 Mozilla Firefox < 67.0.2

MEDIUM 4.3 129101 Mozilla Firefox < 69.0.1

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

lightning.tc.stlukes-hospice.org.uk 96 meteor

6 15 25 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 46

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 125063 KB4499175: Windows 7 and Windows Server 2008 R2 May 2019 Security Update (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (BlueKeep)

CRITICAL 10.0 89757 MS16-035: Security Update for .NET Framework to Address Security Feature Bypass (3141780)

CRITICAL 10.0 64784 Microsoft SQL Server Unsupported Version Detection

CRITICAL 10.0 119612 Security Updates for Microsoft .NET Framework (December 2018)

CRITICAL 10.0 122234 Security Updates for Microsoft .NET Framework (February 2019)

CRITICAL 10.0 117431 Security Updates for Microsoft .NET Framework (September 2018)

HIGH 9.3 111689 KB4343899: Windows 7 and Windows Server 2008 R2 August 2018 Security Update (Foreshadow)

HIGH 9.3 48762 MS KB2269637: Insecure Library Loading Could Allow Remote Code Execution

HIGH 9.3 53382 MS11-025: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)

HIGH 9.3 61535 MS12-060: Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2720573)

HIGH 9.3 87253 MS15-124: Cumulative Security Update for Internet Explorer (3116180)

HIGH 9.3 103137 Security and Quality Rollup for .NET Framework (Sep 2017)

HIGH 9.3 103127 Windows 7 and Windows Server 2008 R2 September 2017 Security Updates

HIGH 8.5 84738 MS15-058: Vulnerabilities in SQL Server Could Allow Remote Code Execution (3065718)

HIGH 8.3 81264 MS15-011: Vulnerability in Group Policy Could Allow Remote Code Execution (3000483) meteor 97 HIGH 7.6 105552 KB4056897: Windows 7 and Windows Server 2008 R2 January 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 108290 KB4088878: Windows 7 and Windows Server 2008 R2 March 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 104892 Security Updates for Internet Explorer (June 2017)

HIGH 7.5 128080 VLC < 3.0.8 Multiple Vulnerabilities

HIGH 7.2 99365 Security and Quality Rollup for .NET Framework (April 2017)

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.9 58333 MS12-021: Vulnerability in Visual Studio Could Allow Elevation of Privilege (2651019)

MEDIUM 6.8 109730 7-Zip < 18.05 Memory Corruption Arbitrary Code Execution

MEDIUM 6.8 130170 Mozilla Firefox < 70.0 Multiple Vulnerabilities

MEDIUM 6.8 126600 Security Updates for Microsoft .NET Framework (July 2019)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.1 18405 Microsoft Windows Remote Desktop Protocol Server Man-in-the-Middle Weakness

MEDIUM 5.0 88651 MS16-019: Security Update for .NET Framework to Address Denial of Service (3137893)

MEDIUM 5.0 92022 MS16-091: Security Update for .NET Framework (3170048)

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 45411 SSL Certificate with Wrong Hostname

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 5.0 111693 Security Updates for Microsoft .NET Framework (August 2018)

MEDIUM 5.0 121021 Security Updates for Microsoft .NET Framework (January 2019)

MEDIUM 5.0 125074 Security Updates for Microsoft .NET Framework (May 2019)

meteor 98 MEDIUM 5.0 105731 Security and Quality Rollup for .NET Framework (January 2018)

MEDIUM 5.0 100056 Security and Quality Rollup for .NET Framework (May 2017)

MEDIUM 4.7 105613 ADV180002: Microsoft SQL Server January 2018 Security Update (Meltdown) (Spectre)

MEDIUM 4.6 109652 Security Updates for Microsoft .NET Framework (May 2018)

MEDIUM 4.3 78447 MS KB3009008: Vulnerability in SSL 3.0 Could Allow Information Disclosure (POODLE)

MEDIUM 4.3 77162 MS14-044: Vulnerability in SQL Server Could Allow Elevation of Privilege (2984340)

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

MEDIUM 4.3 58453 Terminal Services Doesn't Use Network Level Authentication (NLA) Only

MEDIUM 4.3 57690 Terminal Services Encryption Level is Medium or Low

meteor 99 mitchell.tc.stlukes-hospice.org.uk

2 2 9 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 13

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 33850 Unix Unsupported Version Detection

CRITICAL 10.0 86947 VMware ESXi 5.5 < Build 3029944 OpenSLP RCE (VMSA-2015-0007)

HIGH 7.2 99129 ESXi 5.5 < Build 5230635 Multiple Vulnerabilities (VMSA-2017-0006) (remote check)

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.8 88906 ESXi 5.5 < Build 3568722 / 6.0 < Build 3568940 glibc DNS Resolver RCE (VMSA-2016-0002) (remote check)

MEDIUM 6.5 87942 ESXi 5.5 < Build 3248547 Shared Folders (HGFS) Guest Privilege Escalation (VMSA-2016-0001) (remote check)

MEDIUM 6.4 81085 ESXi 5.5 < Build 2352327 Multiple Vulnerabilities (remote check) (POODLE)

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.0 105486 ESXi 5.5 / 6.0 / 6.5 / Multiple Vulnerabilities (VMSA-2017-0021) (VMSA-2018-0002) (Spectre) (remote check)

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.7 111759 ESXi 5.5 / 6.0 / 6.5 / 6.7 Speculative Execution Side Channel Vulnerability (Foreshadow) (VMSA-2018-0020) (remote check)

MEDIUM 4.4 92949 ESXi 5.0 / 5.1 / 5.5 / 6.0 Multiple Vulnerabilities (VMSA-2016-0010) (remote check)

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

mitchell.tc.stlukes-hospice.org.uk 100 nas4free2.tc.stlukes-hospice.org.uk

0 2 6 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 8

SEVERITY CVSS PLUGIN NAME

HIGH 9.3 130907 KB4525237: Windows 10 Version 1803 November 2019 Security Update

HIGH N/A 103569 Windows Defender Antimalware/Antivirus Signature Definition Check

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.4 112116 Security Updates for Windows 10 / Windows Server 2016 (August 2018) (Spectre) (Meltdown) (Foreshadow)

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.7 121035 Security Updates for Windows 10 / Windows Server 2016 (January 2019) (Spectre)

nas4free2.tc.stlukes-hospice.org.uk 101 parallels.stlukes-hospice.org.uk

1 5 9 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 15

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 100760 KB4022715: Windows 10 Version 1607 and Windows Server 2016 June 2017 Cumulative Update

HIGH 9.3 106796 KB4074590: Windows 10 Version 1607 and Windows Server 2016 February 2018 Security Update (Meltdown)(Spectre)

HIGH 9.3 111685 KB4343887: Windows 10 Version 1607 and Windows Server 2016 August 2018 Security Update (Foreshadow)

HIGH 7.6 105548 KB4056890: Windows 10 Version 1607 and Windows Server 2016 January 2018 Security Update (Meltdown)(Spectre)

HIGH 7.5 128080 VLC < 3.0.8 Multiple Vulnerabilities

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.4 112116 Security Updates for Windows 10 / Windows Server 2016 (August 2018) (Spectre) (Meltdown) (Foreshadow)

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.7 121035 Security Updates for Windows 10 / Windows Server 2016 (January 2019) (Spectre)

MEDIUM 4.7 119239 Security Updates for Windows 10 / Windows Server 2016 (September 2018) (Spectre)

parallels.stlukes-hospice.org.uk 102 phantom.tc.stlukes-hospice.org.uk

0 0 5 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 5

SEVERITY CVSS PLUGIN NAME

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 12217 DNS Server Cache Snooping Remote Information Disclosure

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

phantom.tc.stlukes-hospice.org.uk 103 quillipmi.tc.stlukes-hospice.org.uk

1 2 14 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 17

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 33850 Unix Operating System Unsupported Version Detection

HIGH 7.8 80101 IPMI v2.0 Password Hash Disclosure

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 43156 NTP ntpd Mode 7 Error Response Packet Loop Remote DoS

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 97861 Network Time Protocol (NTP) Mode 6 Scanner

MEDIUM 5.0 71783 Network Time Protocol Daemon (ntpd) monlist Command Enabled DoS

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

MEDIUM 4.3 89058 SSL DROWN Attack Vulnerability (Decrypting RSA with Obsolete and Weakened eNcryption)

MEDIUM 4.3 26928 SSL Weak Cipher Suites Supported

MEDIUM 4.3 81606 SSL/TLS EXPORT_RSA <= 512-bit Cipher Suites Supported (FREAK)

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

MEDIUM 4.0 60108 SSL Certificate Chain Contains Weak RSA Keys

quillipmi.tc.stlukes-hospice.org.uk 104 raptor.tc.stlukes-hospice.org.uk

0 0 1 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 1

SEVERITY CVSS PLUGIN NAME

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

raptor.tc.stlukes-hospice.org.uk 105 sabre.tc.stlukes-hospice.org.uk

0 1 11 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 12

SEVERITY CVSS PLUGIN NAME

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 97861 Network Time Protocol (NTP) Mode 6 Scanner

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

MEDIUM 4.3 66848 SSL Null Cipher Suites Supported

MEDIUM 4.3 26928 SSL Weak Cipher Suites Supported

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

sabre.tc.stlukes-hospice.org.uk 106 tcvault1.tc.stlukes-hospice.org.uk

0 0 4 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 4

SEVERITY CVSS PLUGIN NAME

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

tcvault1.tc.stlukes-hospice.org.uk 107 tempest.tc.stlukes-hospice.org.uk

0 0 1 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 1

SEVERITY CVSS PLUGIN NAME

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

tempest.tc.stlukes-hospice.org.uk 108 thunderbolt.tc.stlukes-hospice.org.uk

0 0 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 2

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.0 12085 Apache Tomcat Default Files

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

thunderbolt.tc.stlukes-hospice.org.uk 109 tigercat

2 13 10 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 25

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 125063 KB4499175: Windows 7 and Windows Server 2008 R2 May 2019 Security Update (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (BlueKeep)

CRITICAL 10.0 62758 Microsoft XML Parser (MSXML) and XML Core Services Unsupported

HIGH 9.4 51873 Oracle Document Capture Multiple Vulnerabilities

HIGH 9.3 54841 Data Dynamics ActiveBar ActiveX Controls Code Execution

HIGH 9.3 111689 KB4343899: Windows 7 and Windows Server 2008 R2 August 2018 Security Update (Foreshadow)

HIGH 9.3 48762 MS KB2269637: Insecure Library Loading Could Allow Remote Code Execution

HIGH 9.3 59906 MS12-043: Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (2722479)

HIGH 9.3 87253 MS15-124: Cumulative Security Update for Internet Explorer (3116180)

HIGH 9.3 103127 Windows 7 and Windows Server 2008 R2 September 2017 Security Updates

HIGH 8.3 81264 MS15-011: Vulnerability in Group Policy Could Allow Remote Code Execution (3000483)

HIGH 7.6 105552 KB4056897: Windows 7 and Windows Server 2008 R2 January 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 108290 KB4088878: Windows 7 and Windows Server 2008 R2 March 2018 Security Update (Meltdown)(Spectre)

HIGH 7.6 104892 Security Updates for Internet Explorer (June 2017)

HIGH 7.5 128080 VLC < 3.0.8 Multiple Vulnerabilities

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

tigercat 110 MEDIUM 6.8 109730 7-Zip < 18.05 Memory Corruption Arbitrary Code Execution

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 57608 SMB Signing not required

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 5.0 95657 VMware vSphere Client XXE Injection Information Disclosure (VMSA-2016-0022)

MEDIUM 4.3 78447 MS KB3009008: Vulnerability in SSL 3.0 Could Allow Information Disclosure (POODLE)

MEDIUM 4.3 58453 Terminal Services Doesn't Use Network Level Authentication (NLA) Only

tigercat 111 timetools.tc.stlukes-hospice.org.uk

0 0 5 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 5

SEVERITY CVSS PLUGIN NAME

MEDIUM 6.4 43156 NTP ntpd Mode 7 Error Response Packet Loop Remote DoS

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.8 42263 Unencrypted Telnet Server

MEDIUM 5.0 97861 Network Time Protocol (NTP) Mode 6 Scanner

MEDIUM 5.0 71783 Network Time Protocol Daemon (ntpd) monlist Command Enabled DoS

timetools.tc.stlukes-hospice.org.uk 112 untangle.tc.stlukes-hospice.org.uk

0 0 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 2

SEVERITY CVSS PLUGIN NAME

MEDIUM 5.8 50686 IP Forwarding Enabled

MEDIUM 5.0 12217 DNS Server Cache Snooping Remote Information Disclosure

untangle.tc.stlukes-hospice.org.uk 113 unwinipmi.tc.stlukes-hospice.org.uk

1 2 14 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 17

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 33850 Unix Operating System Unsupported Version Detection

HIGH 7.8 80101 IPMI v2.0 Password Hash Disclosure

HIGH 7.1 20007 SSL Version 2 and 3 Protocol Detection

MEDIUM 6.4 43156 NTP ntpd Mode 7 Error Response Packet Loop Remote DoS

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 97861 Network Time Protocol (NTP) Mode 6 Scanner

MEDIUM 5.0 71783 Network Time Protocol Daemon (ntpd) monlist Command Enabled DoS

MEDIUM 5.0 15901 SSL Certificate Expiry

MEDIUM 5.0 35291 SSL Certificate Signed Using Weak Hashing Algorithm

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

MEDIUM 4.3 90317 SSH Weak Algorithms Supported

MEDIUM 4.3 89058 SSL DROWN Attack Vulnerability (Decrypting RSA with Obsolete and Weakened eNcryption)

MEDIUM 4.3 26928 SSL Weak Cipher Suites Supported

MEDIUM 4.3 81606 SSL/TLS EXPORT_RSA <= 512-bit Cipher Suites Supported (FREAK)

MEDIUM 4.3 78479 SSLv3 Padding Oracle On Downgraded Legacy Encryption Vulnerability (POODLE)

MEDIUM 4.0 60108 SSL Certificate Chain Contains Weak RSA Keys

unwinipmi.tc.stlukes-hospice.org.uk 114 vampire.tc.stlukes-hospice.org.uk

0 0 3 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 3

SEVERITY CVSS PLUGIN NAME

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

vampire.tc.stlukes-hospice.org.uk 115 vcs1.tc.stlukes-hospice.org.uk

0 0 2 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 2

SEVERITY CVSS PLUGIN NAME

MEDIUM 6.4 128033 Apache 2.4.x < 2.4.41 Multiple Vulnerabilities

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

vcs1.tc.stlukes-hospice.org.uk 116 vcs2.tc.stlukes-hospice.org.uk

0 0 1 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 1

SEVERITY CVSS PLUGIN NAME

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

vcs2.tc.stlukes-hospice.org.uk 117 wap1.stlukes-hospice.org.uk

2 5 5 0 0

CRITICAL HIGH MEDIUM LOW INFO

Vulnerabilities Total: 12

SEVERITY CVSS PLUGIN NAME

CRITICAL 10.0 100760 KB4022715: Windows 10 Version 1607 and Windows Server 2016 June 2017 Cumulative Update

CRITICAL 10.0 101366 KB4025339: Windows 10 Version 1607 and Windows Server 2016 July 2017 Cumulative Update

HIGH 9.3 106796 KB4074590: Windows 10 Version 1607 and Windows Server 2016 February 2018 Security Update (Meltdown)(Spectre)

HIGH 9.3 111685 KB4343887: Windows 10 Version 1607 and Windows Server 2016 August 2018 Security Update (Foreshadow)

HIGH 9.3 125058 KB4494440: Windows 10 Version 1607 and Windows Server 2016 May 2019 Security Update (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)

HIGH 9.3 53382 MS11-025: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)

HIGH 7.6 105548 KB4056890: Windows 10 Version 1607 and Windows Server 2016 January 2018 Security Update (Meltdown)(Spectre)

MEDIUM 6.8 63478 Microsoft Windows LM / NTLMv1 Authentication Enabled

MEDIUM 6.4 51192 SSL Certificate Cannot Be Trusted

MEDIUM 6.4 57582 SSL Self-Signed Certificate

MEDIUM 5.0 12217 DNS Server Cache Snooping Remote Information Disclosure

MEDIUM 5.0 42873 SSL Medium Strength Cipher Suites Supported (SWEET32)

wap1.stlukes-hospice.org.uk 118