View all CVEs detected on your assets, and configure Trend Vision One to assess for all CVEson your internal assets, including low-impact CVEs.
NoteThis feature is not available in all regions.
|
Attack Surface Risk Management prioritizes assessment for high-impact and medium-impact
vulnerabilities (CVEs with an impact score range of 31-100). The strategy helps you
focus on the most important remediation tasks to stop potential threat actors from
breaching your network. However, visibility into low-impact CVEs (CVEs with an impact
score range of 0-30) may also be necessary for your organization to meet compliance
requirements or follow internal policies.
Additionally low-impact vulnerabilities may pose high future risks if new exploit
methods emerge. Identifying and addressing low-impact CVEs proactively enhances your
security posture and prevents new sophisticated attacks from affecting your organization.
If you do not have a third-party vulnerability assessment tool connected to Trend
Vision One, you may configure the Trend Vision One vulnerability assessment service
to assess your internal assets for all CVEs, including low-impact CVEs.
In the Vulnerabilities tab of CVE impact score.
or the Risk Factors tab in , click Configure CVE Coverage. You may choose to assess your internal assets for all CVEs or keep the default behavior
of scanning for high-impact and medium-impact CVEs only. To understand how impact
scores are determined, see
NoteIt may take up to 24 hours for new CVE data to display after enabling assessment for
all CVEs on internal assets.
|
In
, the following vulnerability management metrics display data on all detected CVEs:
-
Detected Vulnerabilities: CVEs are calculated and organized by impact score.
-
Internet-facing assets are not currently included in the calculation.
-
-
Mean Time to Patch (MTTP)
-
Average Unpatched Time (AUT)
-
Vulnerable Endpoint Percentage
-
CVE Density
In
, data on all detected CVEs is calculated into the vulnerability percentage and CVE
density metrics. In the Detected Vulnerabilities table, CVEs are counted based on
impact score level. Click the corresponding impact score level to filter detected
CVEs by impact score.
Important
|