Just to be clear, vulnerability assessment tools only scan and list things a platform might be vulnerable too based on certain observables.
They don't necessarily tell you what might be exploitable on a given platform.
For example, the version of Apache and OpenSSH we use in Gaia is considered "old" and vulnerable to some security issues.
However, because of configuration and applied patches, these issues aren't relevant on our system.
Also, if you're just now deploying an R77.x version, know that R77.x will be End of Support in September 2019.
I'd strongly consider deploying a later version that will be supported beyond this date.