← Sectigo cases
Bugzilla #1869056 CCADB Compliance

Sectigo: Inadequate vulnerability scanning and patching

RESOLVED FIXED Sectigo
AI Summary

Sectigo reported deficiencies in their internal vulnerability scanning and patching processes, which resulted in over 400 unresolved vulnerabilities with a CVSS score of 7.0 or higher. The issue arose when agent-based scanning stopped functioning from May 15, 2023, until it was discovered during an ETSI audit in October 2023. The company has since implemented a remediation plan and completed necessary patching, with all critical vulnerabilities resolved by late November 2023. They have also updated their internal processes to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 20:56 UTC Confidence: 0.95
Chronology
  1. Agent-based scanning stopped working without detection.
  2. Vulnerabilities revealed during ETSI audit.
  3. Agent-based scanning re-enabled.
  4. Remaining vulnerabilities deemed false positives.
  5. All critical vulnerabilities resolved.
Participants
Martijn Katerbarg Amir Aamidi Ben Wilson
Similar Local Cases
#1812336 RESOLVED CCADB Compliance Opened 2023-01-25 · Closed 2023-02-10 · 66% similar
Sectigo: Late CCADB update after CPS update
#1597950 RESOLVED CCADB Compliance Opened 2019-11-20 · Closed 2023-02-22 · 57% similar
Sectigo: CCADB failed ALV - Ensured Root CA
#1716670 RESOLVED CCADB Compliance Opened 2021-06-15 · Closed 2024-06-30 · 50% similar
TWCA: Intermediate CA Certificate Missing from Audit Reports
#1567060 RESOLVED CCADB Compliance Opened 2019-07-18 · Closed 2023-02-22 · 49% similar
Sectigo / Web.com: inconsistent disclosure of externally-operated intermediate
#1597947 RESOLVED CCADB Compliance Opened 2019-11-20 · Closed 2023-02-22 · 49% similar
Sectigo: CCADB failed ALV - Network Solutions Certificate Authority
#1894111 RESOLVED CCADB Compliance Opened 2024-04-29 · Closed 2025-01-22 · 48% similar
Entrust: Not updating CPR Problem Reporting Mechanism fields in CCADB
#1757615 RESOLVED CCADB Compliance Opened 2022-03-01 · Closed 2024-06-30 · 48% similar
Amazon Trust Services: Overdue audit statements for intermediate certificates
#1772413 RESOLVED CCADB Compliance Opened 2022-06-02 · Closed 2023-03-20 · 47% similar
eMudhra: Failure to Respond to May 2022 Survey

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action