You can view information about Common Vulnerabilities and Exposures (CVE) instances that are associated with Common Platform Enumeration (CPE) applications, including the most critical CVEs, the CVSSv3 and CVSSv2 scores, and the number of affected applications. You can easily find the computers that are affected by software in your environment.
From the top menu, click Assets> Applications, and then select the CVE Instances tab.
The table lists all CVE instances. You can use the grouping and filtering options to determine the information that is displayed, and the Find Computers button to find computers affected by a CVE instance. To view hidden CPE applications, click the check box next to Include Hidden CPE Applications.
Field |
Description |
---|---|
|
The unique identification number of the CVE instance on the NIST website. |
|
The number of CPE applications which are affected by this CVE instance. |
|
The CVSS v3 score for the CVE instance. The v3 score is used to track the vulnerability level of different findings, and has five tier levels. |
|
The vector associated with the CVSS v3 score. |
|
The unique identification number of the Common Weakness Enumeration (CWE) type on the CWE list. |
|
The CVSS v2 score for the CVE instance. The v2 score is used to track the vulnerability level of different findings, and has three tier levels. |
CVSSv2 Vector |
The vector associated with the CVSS v2 score. |
Matched CPEs |
If the application is matched against a CPE Dictionary item, the matched item’s well-formed name is displayed. |