Hi - I ran an "External vulnerability test" for a security audit for a Doctor's office. After the test completed, my result was a "medium", which im going to try to correct. The only message i received regarding what the actual risk was, is below:
SECURITY ISSUES
Medium -------- (CVSS: 2.6)
NVT: TCP timestamps (OID: 1.3.6.1.4.1........)
It was detected that the host implements RFC1323. The following timestamps were retrieved with a delay of 1 seconds in-between: Paket 1: 127869255 Paket 2: 127870452
Any help would be appreciated - thanx
The probability of someone actually targeting your customer and applying this vulnerability is pretty low, especially given that it is a denial of service exploit, not a method of snooping data. The vulnerability is pretty open and easy, which is likely why the scanner showed it at a medium. The vulnerability is 'open and easy' because it's in a ton of network implementations. I would call this "not a big deal" for the customer as you described.