Asking Security Practitioners: Did You Find the Vulnerable (Mis)Configuration?
Richard Allen May, Christian Biermann, Jacob Krüger, Thomas Leich · 2025
With ever evolving software, reliability and quality assurance are facing growing complexity and security issues.Particularly, interconnected and configurable systems are threatened by (mis)configurations that can lead to exploitable vulnerabilities.Unfortunately, there is limited information on how such configuration vulnerabilities occur or how practitioners deal with these.To tackle this gap, we investigated the connections between (mis)configurations, vulnerabilities, and their treatment by conducting a survey with 41 security practitioners who have encountered configuration vulnerabilities in their work.More precisely, our objectives were to understand the causes, prevalence, severity, and treatments of such vulnerabilities.We found that configuration vulnerabilities are prevalent and severe in practice.They primarily stem from dependency issues, outdated software, and inconsistent (cross-)configurations; are typically influenced by human errors; and are either identified during testing or, in the worst case, during deployment and operation.Generally, configuration vulnerabilities are detected due to security incidents or through word-of-mouth, implying that more preventive security management is required-ideally at an early stage and as part of a holistic security-engineering process.Overall, we aim to enhance the understanding of researchers and practitioners regarding current practices related to handling configuration vulnerabilities as well as open challenges.