Missing TLS 1.2 Minimum Policy Configuration
AWS Elasticsearch domain_endpoint_options not configured with a minimum TLS 1.2 security policy. The domain either uses the default policy (which may allow TLS 1.0/1.1) or has an explicitly weak policy like Policy-Min-TLS-1-0-2019-07. Legacy TLS versions 1.0 and 1.1 are vulnerable to attacks like POODLE, BEAST, and CRIME that exploit weak cipher suites and protocol flaws.