← Chunghwa Telecom cases
Bugzilla #2008799 Self Reported Incident Audit Finding

Chunghwa Telecom: Findings in 2025 WebTrust Audit (GTLSCA) — Missing/insufficient vulnerability scan coverage

RESOLVED FIXED Chunghwa Telecom
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a self-disclosed incident report by Chunghwa Telecom regarding findings from a 2025 WebTrust audit for its GTLSCA operations. The incident was that vulnerability scans were not performed at the frequency required by WebTrust for CA - Network Security v1.7 Criterion 4.3 during the audit period: only one accepted vulnerability scan was performed in Q4 2024, while required quarterly scans for Q1–Q3 2025 were not completed as intended. Chunghwa Telecom stated that the CA Owner (MODA) delegated the remaining quarterly scans to a separate third-party cybersecurity service provider, but inadequate validation of the scanning methodology, scope, and frequency led to one required scan not being performed and to Q2/Q3 scans not fully covering intended systems, resulting in non-compliance identified during the annual audit. Chunghwa Telecom reported that after identification of the non-compliance, GTLSCA completed comprehensive vulnerability scans in accordance with WebTrust requirements, assessed and remediated results, and documented the outcomes. The CA also implemented monitoring mechanisms to track scheduled versus executed scans, validate asset coverage, detect scan failures/exceptions, and added automation and alerting to reduce reliance on manual processes. The bug was resolved as FIXED, with a report closure summary requesting closure after completion of the disclosed action items.

Model: gpt-5.4-nano Generated: 2026-06-13 21:36 UTC Revised: 2026-06-16 18:09 UTC Confidence: 0.90 7 comments
Chronology
  1. Chunghwa Telecom initiated a new annual GTLSCA system maintenance and related services contract with the CA Owner (MODA).
  2. A vulnerability scan was performed for Q4 2024 under the 2024 contract.
  3. Vulnerability scans were not performed for Q1 2025, starting the non-compliance period.
  4. An auditing close meeting identified the non-compliance.
  5. Chunghwa Telecom completed comprehensive vulnerability scans and remediation to end the non-compliance period.
  6. The incident report was scheduled to be closed (final call for comments).
Thread Activity
  1. Cht representative — Opened a preliminary incident report stating vulnerability scans were only performed in Q4 2024 during the audit period and citing WebTrust Criterion 4.3.
  2. Cht representative — Provided a full incident report describing delegation to third parties, inadequate validation leading to missed/incomplete quarterly scans, and a timeline of the non-compliance.
  3. Cht representative — Stated Chunghwa Telecom was monitoring the bug and had no new information.
  4. Cht representative — Updated action items, including performing and validating vulnerability scans, implementing scan execution monitoring, and increasing automation/alerting.
  5. Cht representative — Again stated Chunghwa Telecom was monitoring the bug and had no new information.
  6. Cht representative — Submitted the report closure summary, stating remediation actions were completed and requesting closure after action items were finished.
  7. CCADB representative — Issued a final call for comments or questions and noted the report would be closed around 2026-02-19.
Participants
Cht representative CCADB representative
Similar Local Cases
#2008788 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-11 · 100% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#2008803 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-12 · 100% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
#2009045 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 100% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008788 GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#2012274 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2026-01-24 · Closed 2026-03-08 · 94% similar
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised
#2009046 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 92% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008799 GTLSCA Audit Incident Report #3 - Missing vulnerability scan
#2009048 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 88% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008803 GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
#1904038 RESOLVED Self Reported Incident Revocation Issue Opened 2024-06-21 · Closed 2025-04-18 · 87% similar
Chunghwa Telecom: “Test Website - Valid" URL disclosed to CCADB is expired
#1947034 RESOLVED Policy Document Issue Self Reported Incident Opened 2025-02-09 · Closed 2025-04-11 · 87% similar
Chunghwa Telecom: outdated and stale policy documents disclosed to the CCADB

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action