@shortridge actual conversation I’ve had:
Them: “you have a vulnerability relating to <CVE>”
Me: <reads CVE> “the CVE refers to a file not on <server>, vuln scanner is doing <process I understand *very* well because I use it daily> which only gives a version number. It’s a dumb plugin”
Them: “how will you mitigate?”
Me: “the file referenced does not exist on the server, it is perfectly mitigated”
Them: “when will the vendor fix?”
Me: “never, they do not use that file”
Goto 10, endlessly