Known vulnerabilities (CVE)
A vulnerability is a weakness that can be exploited by a threat actor to perform unauthorized actions within a computer system.
For every device, targets and attempts to match CVEs for:
- Operating System vulnerabilities
- Application vulnerabilities (via third-party VA tools integration only)
- eyeInspect (Operational Technology Plugin integrated sensor or DPI Plugin vulnerabilities)
- Receiving vulnerability scan results only via third-party Vulnerabilities Assessment (VA) tools:
- Tenable.SC v4.0
- Tenable.IO v1.0
- Rapid7 InsightVM (Nexpose) v2.0
- Qualys v2.0
- Receiving the most accurate, updated, and formalized vulnerabilities data from Vedere Labs, NVD and IBM X-Force.
- Automatic re-calculation of Risk Score for new or updated CVEs.
- Common Vulnerability Scoring System (CVSS): CVSS is a standardized rating system to
evaluate and rank reported vulnerabilities. CVSS generates a score between 0 - 10, with
higher scores indicating higher severity, and is based on the following factors:
- Attack Vector
- Attack Complexity
- Privileges Required
- User Interaction
- Scope
- Confidentiality
- Integrity
- Availability
CVSS includes an "Exploitability" subscore rating of low, medium and high based on the combined analysis of Attack Vector, Attack Complexity, Privileges Required, User Interaction, and Scope,
- Exploit Prediction Scoring System (EPSS): EPSS is an open, data-driven effort for estimating the likelihood (probability) that a software vulnerability will be exploited in an unprotected system. EPSS uses current threat information from CVE and real-world exploit data. The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited. uses EPSS for the Vulnerability Exploitability property. For more information about this property, see Risk Exposure Properties.
- CISA: CISA's Vulnerability Scanning (VS) is persistent internet scanning-as-a-service. The VS service continuously assesses the health of your internet-accessible assets by checking for known vulnerabilities, weak configurations—or configuration errors—and suboptimal security practices.
minute read