Sectigo: Inadequate vulnerability scanning and patching
Sectigo reported a self-discovered incident affecting its internal vulnerability scanning and patching. During an ETSI audit, Sectigo became aware that internal agent-based scans were not running properly and that more than 400 previously discovered vulnerabilities (418 with CVSS 7.0 or higher and marked exploitable) had not been acted upon between May 15, 2023 and the end of October 2023. Sectigo stated that internal vulnerability scans were not executed for about five months, while external weekly vulnerability scans on its CA infrastructure were not impacted. Sectigo re-enabled agent-based vulnerability scanning on November 4, 2023, developed a mitigation and remediation plan with dates for patching across datacenters, and applied patches during scheduled maintenance windows. Sectigo reported that patching was completed for DC2, that remaining DC3 vulnerabilities were mitigated through compensating controls (DC3 not directly interacting with certificate systems), and that the remaining six DC1 vulnerabilities were marked as false positives after further patching. The bug was marked RESOLVED with resolution FIXED, and Sectigo reported that two pending action items were completed by January 31, 2024; Mozilla indicated it would close the bug on or about February 2, 2024.
- Agent-based internal vulnerability scanning stopped working without being detected by the IT Security team.
- During an ETSI audit call, Sectigo presented evidence of unresolved high-severity vulnerabilities and discovered the scanning breakdown began on May 15.
- Sectigo re-enabled and confirmed internal agent-based vulnerability scanning was working.
- Sectigo reported a Tenable scan showing 0 critical vulnerabilities.
- Sectigo reported completion of the two remaining action items.
- Sectigo — Sectigo opened an incident report describing deficiencies in internal vulnerability scanning and patching, including impact, timeline, and remediation actions, and set the bug resolution to FIXED.
- Community commenter — A commenter asked whether Tenable had delegated third-party access, and questioned how servers went about five months without updates.
- Sectigo — Sectigo replied that Tenable was self-hosted with access restricted to Sectigo IT/Security, explained the update/patching oversight, and stated they were implementing automated monitoring of Tenable itself.
- Community commenter — The commenter stated they had no further questions.
- Sectigo — Sectigo said it updated internal processes to remove machines properly from Tenable and requested a next update for January 31 due to pending action items.
- Sectigo — Sectigo reported both action items were completed on time and asked if there were further questions.
- Mozilla representative — Mozilla stated it would close the bug on or about Friday, 2-Feb-2024.