We are running authn qualys scans and appear to be receiving quite a few "false positives" related to
CVE-2022-22970, CVE-2022-22971, CVE-2022-22950
While checking the Cisco Security Advisory for CSPC, there is no report related to the above. We would like to declare these as false positives; unfortunately, our risk team needs more concrete evidence. A case was opened with qualys to confirm as false, but, we're caught in a vicious cycle of finger pointing.
I would like to know if anyone on this board has experienced this same scenario with the three listed items.
Thanks in advance for any insight.