The remote host contains one or more unsupported versions of OpenSSL (1.0.2u) on the two bastion hosts serving administrative access to the production VPC. The vendor no longer provides security patches for this branch, so newly disclosed vulnerabilities in this component will not be remediated upstream.
Confirmed by authenticated credentialed scan against bastion-prod-01 and bastion-prod-02. Both hosts are reachable only from the management subnet, which limits exposure but does not remove the risk.
Rebuild both bastion hosts from the hardened AL2023 golden image, which ships OpenSSL 3.0.13 under active vendor support. Cut over one host at a time to preserve administrative access, validate SSH and session-recording agents after each cutover, then decommission the legacy AMI from the account's image catalogue.
Rescan with credentialed checks to confirm the plugin no longer fires, and retain the clean scan output as closure evidence.
| Milestone | Owner | Due | Status | ||
|---|---|---|---|---|---|
| Build and validate AL2023 golden imageImage hardened to CIS L1 and scanned clean | TNT. Nguyen |
2026-06-28 | Complete | ||
| Approve change request CHG-4471CAB approval for the maintenance window | DMD. Mitchell |
2026-07-02 | Complete | ||
| Cut over bastion-prod-01Rebuild complete, SSH and session recording verified | RKR. Kaur |
2026-07-09 | Complete | ||
| Cut over bastion-prod-02Blocked — window slipped twice for unrelated incident response | RKR. Kaur |
2026-07-12 · 25d late | Overdue | ||
| Credentialed rescan and evidence captureConfirm plugin 19506 no longer fires on either host | MPM. Patel |
2026-08-15 · in 9d | Not Started |