QID 730150
Date Published: 2021-08-17
QID 730150: Server Private Keys Detected
An SSH and/or SSL/TLS private keys were detected on the target server.
QID Detection Logic (Unauthenticated):
This QID sends an HTTP GET requests to the target host to see if it hosts any SSH and/or SSL/TLS private keys on Webroot.
Attackers could misuse Private Keys to perform malicious activities such as decrypting sensitive information, and gain unauthorized access to systems etc.
Solution
Customers are advised to store Private Keys in a secure location.
Vendor References
CVEs related to QID 730150
Software Advisories
| Advisory ID | Software | Component | Link |
|---|