05-04-2023 03:35 AM
Hi Team,
The Nessus Scanner in our Network has reported a Vulnerability "HSTS Missing From HTTPS Server (RFC 6797)" under the Plugin ID: 142960.
Recommended Solution: Configure the remote web server to use HSTS.
Link: https://www.tenable.com/plugins/nessus/142960
Solved! Go to Solution.
05-04-2023 04:54 AM
- For starters you are not mentioning your current ISE version : the general approach for Cisco products concerning security bulletins is to upgrade to a later or latest release , especially if your are currently on an older ISE release. Below are a number of possibly related bug reports :
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp54240
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu73993
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv85789
In essence they tell the same , upgrade to latest advisory release for Cisco ISE ; if the problem then remains important for your business , call TAC (make a ticket) .
M.
05-04-2023 04:54 AM
- For starters you are not mentioning your current ISE version : the general approach for Cisco products concerning security bulletins is to upgrade to a later or latest release , especially if your are currently on an older ISE release. Below are a number of possibly related bug reports :
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp54240
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu73993
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv85789
In essence they tell the same , upgrade to latest advisory release for Cisco ISE ; if the problem then remains important for your business , call TAC (make a ticket) .
M.
05-11-2023 07:19 AM
Hi Mate,
Thanks for your response and sorry for not mentioning the current ISE version.
The ISE on my Network is running under the Version 3.0.0.458. Please find few device details below.
06-13-2023 06:16 AM
There is no work around for it. Either HSTS is there or it is not. Originally HSTS was seen as an enhancement and not as a vulnerability by vendors, so they chose not to implement it. Then Nessus and other variables came up where it started to come out in the newer releases.
In this case, you would have to upgrade to a newer code that supports HSTS. Testing an upgrade in your lab and scanning it would probably give you the best results for determining the right path to go down.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide