Vulnerability Findings
The vulnerability findings application provides comprehensive details on identified vulnerabilities, their attributes, and their criticality. This information ensures a robust understanding of risks, enabling prioritization and efficient remediation efforts.
Core Attributes of Vulnerability Findings
Tracking ID
Each vulnerability finding is assigned a unique Tracking ID for identification and referencing within the system.
Vulnerability ID
Vulnerability IDs correspond to standard identifiers, such as CVE (Common Vulnerabilities and Exposures), ensuring consistency and cross-referencing.
Sources
Sources refer to the origins or tools from which vulnerability data is collected and ingested into the VRM system.
Status
The status of findings tracks their lifecycle:
- New: Finding has been enriched and requires triage
- Pending: Finding has been added to a group and will shortly be added to a case
- Open: Finding is associated with a case that still requires the execution of remediation items or further analysis.
- Assigned: Finding is associated with a case and remediation items have been submitted to remediation owners via the defined remediation channels.
- Closed: Finding resolved and no longer posing a risk.
- Exception: Finding marked as acceptable risks under specific circumstances.
Remediation Outcome
You can set the outcome of the finding using drop-down. You can set the following and save:
- False Positive
- Remediated
- Exempted
Asset Reference
Provides a direct link to the associated asset (for example, ACME-CORP\192-WORKSTATION(VAST-92)) to offer context for asset-specific risks and information.
Remediation Advice
Remediation advice as provided by the original vulnerability detection tool. An edit box enables entry of remediation steps or guidance to assist in resolving vulnerabilities as desired. This field serves as a central repository for action plans and remediation strategies and will be provided to remediation owners.
Reassign Asset Feature
The Reassign Asset toggle indicates whether the asset associated with a vulnerability finding can be modified or whether the current assignment is locked. Switching this toggle makes the Vulnerability Asset Reference field editable.
Turbine Risk Score
The Turbine Risk Score evaluates the criticality of a finding based on multiple factors, enabling precise point-in-time prioritization.
You can click on the any of the vulnerability finding for more details.
Turbine Risk Score Visualization
The Turbine Risk Score is displayed through color-coded graphs, enabling quick identification of critical vulnerabilities and understanding of the components that make up the Turbine Risk Score.

Key Components of the default Turbine Risk Score calculation:
- CVSS Base Score: A metric that represents the intrinsic severity of the vulnerability based on standard CVSS scoring.
- EPSS Score: The Exploit Prediction Scoring System estimates the likelihood of a vulnerability being exploited in the wild.
- Public Exploit Found: Indicates if a public exploit exists for the vulnerability.
- Commercial Exploit Found: Identifies whether a commercial exploit (for example, exploit kits sold by attackers) is available.
- Weaponized Exploit Found: Highlights if the vulnerability has been weaponized for widespread attacks.
- CVSS Temporal or Threat Score: Incorporates temporal factors such as availability of exploit code and remediation maturity.
- In Known Exploited Vulnerabilities: Shows if the vulnerability has been listed in databases of actively exploited issues.
- Reported Exploited: Denotes whether exploitation of the vulnerability has been observed.
- Reported Exploited by Threat Actors: Indicates exploitation linked to specific threat actors or groups.
- Reported Exploited by Ransomware: Highlights if the vulnerability has been exploited in ransomware campaigns.
- Reported Exploited by Botnets: Shows exploitation as part of botnet activities.
- Trending on GitHub: Tracks active discussions or exploit code trending on GitHub.
- Asset Criticality: Evaluates the importance of the affected system within the organization’s infrastructure.
- Asset Zone Criticality: Measures the criticality of the physical or logical zone where the asset resides.
Swimlane Intelligence
This section provides a detailed repository of references and intelligence to support analysis and decision-making.
- Vulnerability References: Includes advisories and related information such as vendor advisories.
- Exploits: Offers insights into active exploits associated with the vulnerability.
- Related Attack Patterns: Highlights connections to known attack vectors.
- MITRE ATT&CK Techniques: Maps vulnerabilities to specific techniques within the MITRE ATT&CK framework.
- Common Weakness Enumerations (CWEs): Categorizes underlying weaknesses linked to the vulnerability.
- Vulnerable CPEs: Lists affected configurations or product versions.
For more details about Vulnerability Case Management and Metrics, see Vulnerability Case ManagementVulnerability Case Management and Metrics.Metrics.