Security has sent me this vulnerability on it but my "DR" server hasn't had this issue yet.
"Plugin Output:
HTTP/1.1 404 Not Found
Connection: close
Content-Type: text/html;charset=utf-8
Content-Length: 47
The remote HTTPS server does not send the HTTP
""""Strict-Transport-Security"""" header." The remote web server is not enforcing HSTS. The remote HTTPS server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping man-in-the-middle attacks, and weakens cookie-hijacking protections. Configure the remote web server to use HSTS.
https://www.tenable.com/plugins/nessus/84502
DX NetOps Performance Management: 24.3.3
The 404 page is not configured with HSTS in this version of PM as it contains no data. In the latest release 24.3.11 the 404 page is configured with HSTS.
The 404 page does not contain any data and in the documented release is not configured with HSTS. The current version of Performance Management (24.3.11) has configured the 404 page to use HSTS. The customer can upgrade to the latest version of the product to resolve this issue.