A vulnerability is a CVE that affects at least one of your assets. Its page shows how severe the CVE is, whether it is known to be exploited, which of your assets it affects and in what state, and the full CVE record.

Before You Start

  • Package: External Attack Surface Management (EASM).
  • Role: Admin or Member.

Where to Find It

Sidebar: EXTERNAL ATTACK SURFACE MANAGEMENT › VULNERABILITIES · Tab: VULNERABILITIES LIST · https://platform.deepinfo.com/app/easm/vulnerabilities

Select a CVE to open its drawer, then select OPEN IN NEW TAB. You can also reach the page from:

  • quick view on VULNERABILITIES LIST: OPEN IN NEW TAB above the selected CVE;
  • the MOST CRITICAL VULNERABILITIES and MOST SEEN VULNERABILITIES rows on the EASM dashboard and on the Vulnerabilities OVERVIEW tab, and TOP VULNERABILITIES on its INSIGHTS tab;
  • an asset's VULNERABILITIES tab (see Investigate an asset).

The page address is https://platform.deepinfo.com/app/easm/vulnerabilities/<CVE ID>.

Read the Screen

The header of a CVE page for a CVE in the CISA KEV catalogue, with the EXPLOITABLE strip, the KEV block and the tabs.

Header. The breadcrumb EASM / VULNERABILITIES / followed by the CVE ID, then:

  • the score and severity, and a CERTAIN or POTENTIAL flag;
  • the CVE ID, the CWE name and number, and the C/I/A chip (the impact on confidentiality, integrity and availability);
  • for a CVE in the CISA KEV catalogue, a red EXPLOITABLE strip that says a weaponized exploit is somewhat likely, and a block with the vulnerability's name, the vendor and product, ADDED TO KEV, REMEDIATION DUE, REQUIRED ACTION, SHORT DESCRIPTION and NOTES.

Tabs: OVERVIEW, ASSETS and VULNERABILITY INFO.

OVERVIEW

Card What it shows
INFO VENDOR / PRODUCT: the first affected vendor and product, with a count of the others. EPSS SCORE, PUBLISHED DATE and LAST MODIFIED DATE
CVSS SCORE The CVSS base score on a 0–10 gauge, with the severity
AFFECTED ASSETS How many of your assets the CVE affects, with the count per asset type

ASSETS

The ASSETS tab of a CVE page with the SUBDOMAINS chip selected and the list of affected assets with their states.

  • Header: the number of assets, EXPORT (not available on this tab; see Good to Know) and VIEW SETTINGS.
  • Chips: ALL, DOMAINS, SUBDOMAINS, IP ADDRESSES and WEBSITES.
  • Columns: ASSET NAME, STATE, FIRST SEEN and LAST SEEN. The columns do not sort.

The tab lists the assets where the CVE is active. Select a row to open the asset drawer.

VULNERABILITY INFO

Section What it shows
IMPACT PROFILE The impact on confidentiality, integrity and availability
WEAKNESS IDENTITY The CWE, with its description, impact and related CAPEC entries
ATTACK PROFILE ATTACK VECTOR, ATTACK COMPLEXITY, PRIVILEGES REQUIRED, DESTINATION and SCOPE
DETECTION & FORENSICS DETECTION METHOD, ATTACK STAGES, ANALYSIS DATE and CVE ORIGIN
AFFECTED PRODUCT The affected products
META INFO CVE ID, ASSIGNER, PROBLEM TYPE, REFERENCES and DATA VERSION

Decide What to Do About a CVE

  1. In the header, check whether the CVE is EXPLOITABLE. If it is, read REQUIRED ACTION and note the REMEDIATION DUE date.
  2. On OVERVIEW, check the CVSS SCORE and the EPSS SCORE.
  3. On ASSETS, see which assets are affected. Narrow the list with a chip and open each asset to check it.
  4. Fix the CVE on the asset, or record your decision: select the asset's STATE chip and choose a state. The state applies to this CVE on this asset only. See Change the state of issues and vulnerabilities.

To change the state of several vulnerabilities at once, use the VULNERABILITIES tab of an asset; see Investigate an asset.

States, Colours and Scores

Signal Scale Meaning
Score and severity 0–10 The CVSS base score
EPSS SCORE percentage The CVE's EPSS value
EXPLOITABLE yes or no The CVE is in the CISA KEV catalogue
CERTAIN flag "This vulnerability has been verified through testing and confirmed as valid."
POTENTIAL flag "This vulnerability has been identified through testing but not yet confirmed."
NEW badge First detected on your assets in the last 7 days

These scales are not the security score. See Prioritize vulnerabilities and How security scores work.

Good to Know

  • Check the CVE ID in the address. The address of a CVE ID that does not exist, for example a mistyped one, can still open a page with no data, without an error: a score of 0, no assets and today's date as the published date.
  • To export the affected assets, use the EXPORT button on the ASSETS tab of the CVE drawer, which opens from VULNERABILITIES LIST.
  • VENDOR / PRODUCT shows only the first product in the CVE's list. For the full list, open VULNERABILITY INFO › AFFECTED PRODUCT.

Do This With the API

Last updated