This finding has not been triaged. Decide whether it becomes a POA&M item, is dismissed as a false positive, or is merged into an existing finding.

The internal API gateway negotiates TLS_RSA_WITH_AES_128_CBC_SHA and three other CBC-mode cipher suites during the TLS handshake. These suites do not provide forward secrecy and are explicitly disallowed by the system's cryptographic baseline, which requires AEAD suites with ECDHE key exchange.

Both gateway nodes accept the weak suites on 443/TCP. The gateway is reachable from tenant workloads inside the VPC but not from the public internet, which reduces exposure without removing it.

Plugin 42873 — SSL Medium Strength Cipher Suites Supported (SWEET32) Host: 10.42.4.20 (443/TCP) Medium Strength Ciphers (> 64-bit and < 112-bit key) TLS_RSA_WITH_AES_128_CBC_SHA AES-128-CBC SHA1 TLS_RSA_WITH_AES_256_CBC_SHA AES-256-CBC SHA1 TLS_RSA_WITH_3DES_EDE_CBC_SHA 3DES-CBC SHA1 TLS_ECDHE_RSA_WITH_3DES_EDE_CBC 3DES-CBC SHA1

Restrict the gateway's TLS policy to the approved AEAD suite list, reload the listener configuration, and rescan to confirm the plugin no longer fires against either node.

SC-8 — Transmission Confidentiality and Integrity SC-13 — Cryptographic Protection
Asset IdentifierHostnameTypeEnvironmentPortIn Inventory
10.42.4.20apigw-prod-01Virtual machine Production443/TCP Matched
10.42.4.21apigw-prod-02Virtual machine Production443/TCP Matched
Asset identifiers are reconciled against the Integrated Inventory Workbook on each import.
CSV
nessus-2026-08-04-export.csv
2.8 MB·Auto-attached
PNG
handshake-capture.png
410 KB·M. Patel
Marcus Patel viewed the finding
2026-08-05 14:12
Marcus Patel attached handshake-capture.png
2026-08-05 14:10
Scan ingest created the finding from nessus-2026-08-04-export.csv
2026-08-04 02:15 · automated import
Finding Detail
Finding IDFND-0318
SeverityModerate
Triage statePending
SourceVulnerability Scan
DetectorTenable Nessus
Source ID42873
CVE
CVSS v3.16.5
Detected2026-08-04
SystemNorthwind GovCloud
Triage Decision