Vulnerability Findings - Support Tab
This tab provides key details regarding vulnerability findings, affected assets, risk assessments, and remediation targets. This tab allows security analysts to track and manage vulnerabilities effectively.
By default, the Support Tab is Read-Only. To make changes, uncheck the "Read Only" box. After modifications, recheck "Read Only" and click "Save" to apply updates.
Key Sections:
- Vulnerability Finding Supporting Data
- Unique ID Type: Categorization of the vulnerability.
- Unique ID: Specific identifier.
- Scan ID: Reference ID from the scanner.
- Grouping Status: Identifies if the vulnerability is grouped.
- Flow Automation: Indicates if remediation is automated.
- Summary: Provides a brief description.
- Asset Information
- Primary Asset Identifier: Unique ID of the affected asset.
- Hostname & IP Address: Identifies the impacted device.
- Asset Zone & Criticality: Defines importance and risk level.
- Reassign Asset: Specifies if asset assignment can be changed.
- Asset SLA Targets: Defines the time required to remediate vulnerabilities based on severity (defined by asset information):
- Critical
- High
- Medium
- Low
- Risk Score Data
- Turbine Risk Score: Score out of 1000.
- Risk Score Label: Severity classification (Critical, High, Medium, Low).
- Raw Risk Score: CVSS and EPSS-based scoring.
- Merged Risk Scores: Breakdown of calculated risk values.
- Scanner Raw Data
- Contains detailed scan results from security tools (e.g., Tenable, Rapid7, Qualys).
- Helps analysts validate vulnerability findings.
- References: Lists exception references for exclusions or policy-based modifications.