Qualys QIDs 38173 and 38170 flag SSL vulnerabilities for VMSP components on ports 30005, 30006
search cancel

Qualys QIDs 38173 and 38170 flag SSL vulnerabilities for VMSP components on ports 30005, 30006

book

Article ID: 446997

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

Qualys security scanners report the following vulnerabilities on ports 30005 and 30006 of VMSP components, including Fleet Manager and Identity Broker (vIDB):

  • QID 38173 - SSL Certificate - Signature Verification Failed.
  • QID 38170 - SSL Certificate - Subject Common Name Does Not Match Server FQDN

Environment

VMware Cloud Foundation 9.1

Cause

The VMSP platform operates a private Public Key Infrastructure (PKI) by design. Certificates on ports 30005 and 30006 are generated and signed by an internal Certificate Authority (vcf-cluster-issuer). External scanners flag the signature verification as failed (QID 38173) and subject common name mismatch (QID 38170) because the internal CA is not present in public or external scanner trust stores. Broadcom Engineering confirmed that ports 30005 (Control Plane Health Check API) and 30006 (Control Plane Webhook API) are utilized strictly for internal operations between the VMSP components and the Platform runtime.

Resolution

Broadcom Engineering plans to implement a network restriction in future release. Access to these ports will be limited to the VSP management cluster IP Pool. External access will be restricted, preventing external scanners from routing to them and flagging these QIDs.

Additional Information

It is recommended to subscribe to this article to be updated on the fix status. For instructions on how to subscribe, refer to  Subscribe to a Broadcom knowledge article by article or product