PCI scans are pretty ruthless about requiring infrastructure that is current (to obtain all available security patches) and supported (to ensure availability of future security patches). UTM is lagging on multiple fronts, although support has argued that many of the problems are fixed with backports.
Is anyone prepared to document the target infrastructure for v9.5, with the hope that the answer will make PCI scanners happy. This is a list of the embedded components that come to mind. Based on the confirmed Moderate-to-High patches for these products, I have indicated what the "correct' answer should be:
- Openssl? PCI will expect OpenSSL 1.1.0e or OpenSSL 1.0.2k (which fixes a CVE announced February 16, 2017)
- OpenSSH? My PCI scan vendor has been requiring at least 7.4 for many months
- Firefox (used for HTML5 VPN Web Resources)? PCI will expect 52.0.1 (released March 17, 2017)
- PostGress SQL? PCI will expect 9.5.4 or 9.4.9 or 9.3.14 or 9.2.18 or 9.1.23
- Apache Tomcat? PCI will ask for 7.0.77 for production, but it was only released this month. We should expect at least 7.0.75 for the Beta test, since it was released in January.
Similarly for any components not listed due to my ignorance -- will they be patched to include all recent moderate-to-high CVE risks?