Search

Contact Us

Log in

Vulnerabilities / HSTS header with low duration and no subdomain protection

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Severity
low
CWE NameHSTS header with low duration and no subdomain protection
CWE IDCWE-319
CWE Score4.8
Compliance
OWASP TOP10 -> A2, A5
PCI-DSS -> 4.1, 6.5.4
ISO 27001 -> A.5.14, A.8.9, A.8.24
HIPAA -> 164.306(a), 164.312(c)(1), 164.312(e)(1)
CVSS3.0
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
Confidentiality ImpactLow
Integrity ImpactLow
Availability ImpactNone
HSTS header with low duration and no subdomain protection