@neil @stefano "Here's an automated scan, if there are any false +vs you need to provide proof for each one individually."
"We're running a fully up to date RHEL 9, please exclude all the known false +vs for that OS"
"We don't do that, you need to provide proof for each individually"
I mean, these people are getting paid to do these scans, surely the least they could do is maintain a database of false +vs for common OSes so they could be automatically excluded?! (spoiler: none of them do!)
@neil @stefano Basically money for old rope - a not insignificant amount of money paid to just push the "start" button on the scanner, produce an automatic 300 page report and generate a crap-ton of work for someone else!