Skip to main content

User Knowledge Base

Advanced Analytics - CVE Catalog 

The CVE Catalog uses BlueVoyant detection to identify CVEs (Common Vulnerabilities and Exposures) in your vendor environment.  

The Catalog is in the Client Portal > Advanced Analytics.

image219.png
image220.png

The CVE Catalog shows all CVEs that affect your monitored third-party companies.

image221.png
CVE Information:
  • CVE – Identifier assigned to each CVE (in the format CVE-year-1234567) 

  • CVSS v3.1 Score - A Common Vulnerability Scoring System (CVSS) v3.1 score is a value between 0.0 and 10.0 for the severity of a vulnerability 

  • CVSS v3.1 Severity - The Common Vulnerability Scoring System (CVSS) v3.1 severity ratings are: 

    • None: 0.0 

    • Low: 0.1–3.9 

    • Medium: 4.0–6.9  

    • High: 7.0–8.9 

    • Critical: 9.0–10.0 

  • Published Date – Date when the CVE was published by the National Vulnerability Database (NVD) 

  • Last Observed – Date when the CVE was last detected by BlueVoyant in your environment of monitored companies 

  • Confidence Rating – The BlueVoyant Analytics team assigns a confidence rating to each CVE. 

    Confidence:
    • LOW - We can validate only a software version from the CVE data, and this does not give confidence that the CVE is a risk.

    • HIGH - We detected many elements of risk from the CVE. For example: services required to exploit the vulnerability, configurations that can be detected, and other detections that can be evidence of malicious actions. We have a lot of confidence that this CVE describes a real risk.

    • MEDIUM - The version is enough to detect the vulnerability in systems, but a malicious exploit requires much more.

  • Known Exploited Vulnerability – If the CVE was added to the KEV Catalog (Known Exploited Vulnerability catalog) 

  • KEV List Date = Date when the CVE was added to KEV catalog 

  • Companies Exposed – Total monitored companies affected by this CVE