Vulnerabilities reported in AKS VMSS nodes

Copper Contributor

Hi all,

Within ASC and "Vulnerabilities in security configuration on your machines should be remediated" my AKS nodes are being reported as requiring remediation.

 

If I were to remediate these they'll just come back if I scale out/in or upgrade? Also, as these are AKS nodes, shouldn't they be excluded or be patched already?

 

Name

State

 

Disable SMB V1 with Samba

Critical

Open

Run AuditD service

Critical

Open

IP forwarding should be disabled. (net.ipv4.ip_forward = 0)

Critical

Open

 

Anyone else experienced this? Or remediated?

1 Reply

According to Azure support this is by design and they don't have plans to change it, many other users have this issue too, apparently... 

 

I've put it on Azure feedback if anyone wants to vote it up https://feedback.azure.com/forums/347535-azure-security-center/suggestions/40878643-vm-scale-sets-ma...