23 days past the scheduled completion date. Critical findings must be remediated within 30 days of original detection. Update the schedule with a justification, or submit a deviation request.

The remote host contains one or more unsupported versions of OpenSSL (1.0.2u) on the two bastion hosts serving administrative access to the production VPC. The vendor no longer provides security patches for this branch, so newly disclosed vulnerabilities in this component will not be remediated upstream.

Confirmed by authenticated credentialed scan against bastion-prod-01 and bastion-prod-02. Both hosts are reachable only from the management subnet, which limits exposure but does not remove the risk.

Rebuild both bastion hosts from the hardened AL2023 golden image, which ships OpenSSL 3.0.13 under active vendor support. Cut over one host at a time to preserve administrative access, validate SSH and session-recording agents after each cutover, then decommission the legacy AMI from the account's image catalogue.

Rescan with credentialed checks to confirm the plugin no longer fires, and retain the clean scan output as closure evidence.

2 engineering days (Platform team) plus a 2-hour maintenance window approved through the standard change process. No additional licensing or spend.
bastion-prod-01 · 10.42.1.14 bastion-prod-02 · 10.42.1.15
Asset IDs match the Integrated Inventory Workbook.

FND-0311 · Unsupported OpenSSL version detected Tenable Nessus · plugin 19506 · detected 2026-06-14 · scan cycle 2026-06 monthly Critical
3 of 5 milestones complete
60%
MilestoneOwnerDueStatus
Build and validate AL2023 golden imageImage hardened to CIS L1 and scanned clean
TNT. Nguyen
2026-06-28 Complete
Approve change request CHG-4471CAB approval for the maintenance window
DMD. Mitchell
2026-07-02 Complete
Cut over bastion-prod-01Rebuild complete, SSH and session recording verified
RKR. Kaur
2026-07-09 Complete
Cut over bastion-prod-02Blocked — window slipped twice for unrelated incident response
RKR. Kaur
2026-07-12 · 25d late Overdue
Credentialed rescan and evidence captureConfirm plugin 19506 no longer fires on either host
MPM. Patel
2026-08-15 · in 9d Not Started
Drop evidence files here, or browse
PDF, XLSX, DOCX, PNG, JPG, LOG, ZIP · up to 100 MB · versions are retained
PDF
patch-report-aug.pdf
1.4 MB·v2·T. Nguyen
Pending Review
LOG
bastion-01-cutover.log
318 KB·v1·R. Kaur
Approved
PNG
openssl-version-after.png
642 KB·v1·R. Kaur
Approved
DOCX
CHG-4471-approval.docx
84 KB·v1·D. Mitchell
Approved
DM
RK
Rina KaurPlatform EngineerAug 4, 3:18 PM
Second cutover slipped again — the maintenance window collided with the INC-2214 response on Friday. Next available window is Aug 14. @Dana Mitchell do we need a deviation request given we're already past the 30-day mark?
DM
Dana MitchellISSOAug 4, 4:02 PM
Not a deviation — the risk hasn't changed, only the schedule. Update the scheduled completion date to Aug 20 with the incident as the documented justification, and note it in the monthly ConMon submission. If Aug 14 slips too, we escalate.
TN
Tomas NguyenSecurity AnalystAug 6, 8:56 AM
Uploaded patch-report-aug.pdf covering the host-01 rebuild. Host-02 section is a placeholder until the cutover lands, so please don't approve this version as closure evidence yet.
Tomas Nguyen uploaded evidence patch-report-aug.pdf (v2)
2026-08-06 08:56 · 10.42.8.31
System flagged the item as past due
2026-07-15 00:00 · scheduled job
Rina Kaur updated Scheduled Completion Date
2026-07-052026-07-14
2026-07-02 11:20
Dana Mitchell changed Status
OpenIn Progress
2026-06-20 09:14
Dana Mitchell assigned the item to Rina Kaur
2026-06-18 16:45
Dana Mitchell created the POA&M item from finding FND-0311
2026-06-16 10:02
POA&M Detail
POA&M IDPOAM-0142
StatusIn Progress
Original RiskCritical
Adjusted RiskNot adjusted
ControlsRA-5 SC-13
Point of Contact
RKRina Kaur
Detector SourceTenable Nessus
Source Identifier19506
CVECVE-2026-0714
Dates
Original Detection2026-06-14
Scheduled Completion2026-07-14
Status Date2026-08-06
Remediation Window30 days (critical)
Vendor Dependency
DependentNo
Product
Last Check-in
Deviation
Risk AdjustmentNo
False PositiveNo
Operational Req.No
Rationale
BOD 22-01
KEV ListedYes
BOD Due Date2026-07-05
Watchers
DMRK TNMP +2