Not to be confused with ISMS › Risk Management › Vulnerabilities: that is
the catalog of abstract vulnerabilities used to build risks. CVE Analysis
works with concrete, published vulnerabilities that the matching assigns to
your systems.
CVSS and severity
If both are present, the severity applies; if only the number is present, the
level is derived from it — from 9 critical, from 7 high, from 4 medium, below
that low. The same thresholds determine the Remediation Deadline.
By CVEs and by Assets
The inventory stands in two lists:- By CVEs — one row per vulnerability. A click in the CVE ID column opens it.
- By Assets — one row per affected system, with the full distribution across all four severity levels.
CVSS metrics
The Overview tab shows the CVSS value, the level in plain text and a grid with the individual metrics of the rating. If the vulnerability has neither a severity nor metrics, Not Rated stands in place of the level.Two vulnerabilities rarely show the same metrics. Only what the source
supplies is shown, and each vulnerability fills only one CVSS version. The grid
lists the metric names of versions 2, 3 and 4 side by side: Attack
Complexity, Privileges Required and User Interaction belong to versions 3
and 4, Scope only to version 3, Access Complexity and Authentication only
to version 2, Attack Requirements only to version 4. Version 4 splits the
impacts into the vulnerable system and subsequent systems, for example
Confidentiality (Vulnerable System) and Confidentiality (Subsequent
Systems); these six rows replace Scope, Confidentiality, Integrity and
Availability there. For version 4, only the base metrics appear. Which version the rating followed is stated as version and vector
above the grid and, in addition, in its first row CVSS Version; that row’s
info icon explains the scale of the version — for version 2 also that it has
no Critical level and High is the highest.
Recording an assessment
On the detail page of a vulnerability, only the Assessment tab accepts entries: a pencil icon next to a section heading switches it into edit mode, recognizable by the Editing CVE bar. The Journal tab holds the change history of the vulnerability.The Relations tab lists all of the vulnerability’s relations, grouped. It is
the same view as under Inventory › Relationships; columns and
handling are described there.
Status
New · Assessed · In Progress · Resolved · Accepted · False Positive Two optional entries go with it, neither of which affects the status: Responsible for who takes care of it and Due Date for the deadline.The save button also stays disabled while nothing has changed, or while Due
Date holds an unreadable date.
Remediation deadline and due date
The Remediation Deadline in the General section cannot be entered — it is calculated from the CVSS value:A Remediation Deadline of seven days can sit next to a Due Date three
months out. The deadline follows from the severity, the due date from your own
agreement; the deadline takes neither the date nor the status into account.
Risk assessment
The Risk Assessment section carries the same risk matrix as the ISMS, here with the vulnerability as its subject.If nothing has been assessed yet, only a sentence stands there — the matrix
appears only once you switch to edit mode.
Assessing several CVEs
In the By CVEs list you assess several vulnerabilities in one step. Edit opens the same fields as the Assessment tab for the selected rows; the By Assets list has no selection. With one selected row, the fields are prefilled with that vulnerability’s values. With several rows they are empty, and each field has a check box in front of it.Only checked fields are written. The other fields of the selected
vulnerabilities stay unchanged, even though the form shows them empty.
Multi-edit does not process more than 1000 selected rows; Edit then stays
disabled. The same limit applies when you select all rows through a filter.
Controls
In the Controls tab, the Control button opens the Add Control dialog: Create New creates a new one, Link Existing picks one that already exists. Above the list you see how many of the linked controls are implemented.The tab is a second view of the same data as under
ISMS › Controls, not a control management of its own.
The same control can treat a vulnerability and satisfy a compliance objective.
Remove Relation only dissolves the relation between the vulnerability and the
control; the control itself stays in the ISMS.
Affected Assets and Software
Affected Assets names the systems, Affected Software the individual installations with version and host.The Overview tab has a similarly named section, Affected Products. It
names something else: the product data of the vulnerability itself —
Vendor, Product, Version, Vulnerable — regardless of whether that
product is installed in your inventory.