Remediation

Weak cipher suites enabled

The endpoint accepts weaker CBC-era cipher suites. Modern public HTTPS endpoints should prefer AEAD suites such as AES-GCM or ChaCha20 and avoid keeping older CBC suites enabled unless there is a documented compatibility requirement.

What this usually means

Fix path

Safe rollout advice

Verify after change