UnlockSec

Sample Assessment Report

Redacted for confidentiality

Q1 2025

VAPT

Vulnerability Assessment & Penetration Testing

Client

Confidential Client — Financial Services

Scope

External network perimeter (45 IPs), internal segmented network (3 VLANs), 2 web applications

Duration

10 business days

Standard

PTES (Penetration Testing Execution Standard)

Executive Summary

UnlockSec conducted a comprehensive vulnerability assessment and penetration test of the client's external and internal network infrastructure over a 10-day engagement. The assessment identified 3 Critical, 7 High, and 14 Medium findings. The most significant finding was an unauthenticated remote code execution vulnerability on a legacy VPN concentrator that provided direct access to the internal network. All critical and high findings were retested and verified remediated within 15 days of the initial report.

Methodology

PTES (Penetration Testing Execution Standard)NIST SP 800-115OWASP Testing Guide v4.2MITRE ATT&CK Enterprise

Sample Findings

VAPT-001

Unauthenticated RCE — Legacy VPN Concentrator

Critical

Description

The Fortinet FortiGate device (v6.0.3) is affected by CVE-2022-42475, a heap-based buffer overflow vulnerability in the SSL-VPN component allowing unauthenticated remote code execution. Exploitation provides root-level access to the device and a pivot point into the internal network.

Recommendation

Upgrade FortiOS to version 7.2.3 or later immediately. Apply network-level controls to restrict management plane access to authorised IP ranges. Review logs for indicators of exploitation.

VAPT-002

Default Credentials — Network Management Interface

Critical

Description

The Cisco Catalyst switch management interface (10.x.x.x) is accessible with factory default credentials (admin/admin). An attacker with network access can authenticate and modify switch configuration, enabling VLAN hopping or traffic interception.

Recommendation

Immediately rotate all network device credentials. Implement a privileged access management (PAM) solution. Restrict management interface access to a dedicated out-of-band network.

VAPT-003

SMB Relay Attack — Domain Credential Capture

High

Description

LLMNR and NBT-NS poisoning are enabled across workstation subnets. An attacker positioned on the internal network can capture NTLMv2 challenge-response hashes and relay them to authenticate to other systems without cracking the underlying password.

Recommendation

Disable LLMNR and NBT-NS via Group Policy. Enable SMB signing on all hosts. Deploy network-based detection for LLMNR poisoning attempts.

VAPT-004

Outdated TLS Configuration — Customer Portal

Medium

Description

The customer-facing portal supports TLS 1.0 and 1.1 in addition to TLS 1.2. These older protocol versions are susceptible to POODLE and BEAST attacks and are deprecated per RFC 8996.

Recommendation

Disable TLS 1.0 and 1.1. Configure the server to support TLS 1.2 and 1.3 only, with strong cipher suites. Test changes in staging before production deployment.

* Showing 4 of 38 total findings. Full report provided upon engagement.

Risk Summary

Critical3
High7
Medium14
Low9
Info5
Total Findings38

Deliverables Included

  • Executive summary report (board-ready, non-technical)
  • Full technical findings report with CVSS scores
  • Vulnerability evidence packs (screenshots, PoC code)
  • Remediation priority matrix
  • Unlimited retest reports until all findings are closed

Ready for a real assessment?

Get a tailored VAPT engagement led by certified operators with unlimited retests.

Request AssessmentView All Services