
Explanation:
To determine the server to be patched within 14 calendar days and the appropriate technique and mitigation, the decision will be based on the CVSS risk level, the environment, and the organization's remediation standards.
Analysis:
1. CVSS Standards for Remediation Timeframes
* CVSS > 9.0: Must be remediated within 7 calendar days.
* CVSS > 7.9 and ≤ 9.0: Must be remediated within 14 calendar days.
2. Vulnerabilities and CVSS Scores (From Output Tab)
* 192.168.76.5: CVSS 9.2 (Unsupported software version). Must be remediated within 7 days (not applicable here for the 14-day timeline).
* 192.168.76.6: CVSS 7.4 (Session sidejacking). Falls under the 30-day timeframe, not within 14 days.
* 192.168.50.5: CVSS 8.1 (Untrusted SSL certificate). This requires remediation within 14 days.
* 192.168.50.6: CVSS 7.4 (Session sidejacking). Falls under the 30-day timeframe.
* 192.168.60.5: CVSS 8.1 (Untrusted SSL certificate). This requires remediation within 14 days.
* 192.168.60.6: CVSS 7.4 (Session sidejacking). Falls under the 30-day timeframe.
3. Environment (From Environment Tab)
* 192.168.50.5: UAT environment, external. Publicly accessible and requires attention.
* 192.168.60.5: Production environment, external. Publicly accessible and high priority for patching.
Recommended:
Server to be patched within 14 days: 192.168.60.5 (Production environment has a higher priority than UAT).
Technique and Mitigation: Patch and upload a signed certificate from a trusted third-party provider.