We had a PCI security audit of an existing VIP on our ACE 4710. The VIP is set up as HTTPS terminating on the ACE with a http redirect for all 80 traffic. The audit reported this VIP was vunerabled to the Cisco "IOS HTTP Authorization Vulnerability". Which basicly states, http Management is on this IOS device. It does not make any sense, as the VIP is pointed to a pair IIS servers, Any ideas?
It turns the webserver behind the VIP, was returing a page when you sent a HTML GET to https://www.mysite.com/level/16/exec/- This was being a recoded as a security vulnerability. Thanks for the sanity check!