We run 4 cPanel servers (latest stable release). The latest PCI-DSS scan failed because of CVE 2013-3587 (BREACH attack)
ref: http://breachattack.com/
Our scanner provider asked for an official response from cPanel regarding this because the scan indicated port 2087, 2083 and 2096 are vulnerable to this attack.
Quote:
"BREACH attack requires HTTP compression, reflection of user input in response headers, and reflection of secrets in response headers. If cPanel does not implement all three of those things, the site is not susceptible. Please reach out to cPanel to confirm and send us their response."
ref: http://breachattack.com/
Our scanner provider asked for an official response from cPanel regarding this because the scan indicated port 2087, 2083 and 2096 are vulnerable to this attack.
Quote:
"BREACH attack requires HTTP compression, reflection of user input in response headers, and reflection of secrets in response headers. If cPanel does not implement all three of those things, the site is not susceptible. Please reach out to cPanel to confirm and send us their response."