This translation has not been editorially reviewed yet. The German version is authoritative. Deutsche Fassung →
Why this audit area never reports "critical"
This audit area never assigns the "critical" level. The highest classification used is "severe", and it only applies with demonstrable end of maintenance — backed by a maker statement, not an estimate.
- The reason is a limit of the method: the module knows a version is visible. Whether it IS vulnerable, it doesn't know. A critical finding on this basis would be a claim with no evidence.
- Visible version values are therefore classified as "medium" at most. That's not downplaying it — it's an honest reflection of what was actually established.
- This restraint is the same line held across the whole service: a false positive costs trust in every other finding. A cautious classification with a clear justification beats a dramatic one with none.
FAQ
Do we get a list of known security holes?
No. That would need matching the version to a vulnerability database, and certainty that the detected version is the one actually installed. Passive observation can't deliver either.
So why do you report visible versions at all?
Because they make automated matching easier. That's a verifiable fact and a useful pointer — just not a critical finding.