Schwachstellen-Karten

Vulnerability Intelligence Cards (aka Vulnerability Cards) provide an on-demand summary of essential information related to a specific Vulnerability, and are updated in real time as Recorded Future collects new information. You can use Vulnerability Cards as a starting point when assessing whether this Vulnerability poses a specific risk to your organization, and further can be used in identifying associated indicators of compromise. Vulnerability Cards are also pivot points during investigations that start with another indicator, a malware, or a threat actor.

Beschreibungen mehrerer allgemeiner Komponenten der Schwachstellenkarte finden Sie in der Übersicht über Intelligenzkarten. Die folgenden Details sind spezifisch für die Schwachstellenkarte:

Risiko-Score und Risiko-Score-Verlaufsdiagramm:

For CVEs, the Vulnerability card presents a vulnerability risk score determined by several factors that Recorded Future considers, including the CVSS. More information can be found by looking at the Vulnerability Risk Rules.

mceclip9.png
  


Jede CVE enthält ein Diagramm, das visualisiert, wie sich die Risikobewertung der CVE im Laufe der Zeit verändert hat. Wenn Sie den Mauszeiger über einen beliebigen Tag im Diagramm bewegen, wird die Risikobewertung für die CVE an diesem bestimmten Tag angezeigt und die Kritikalität der CVE an diesem bestimmten Tag angezeigt. Die Verwendung des Verlaufsdiagramms der Risikobewertung kann dabei helfen, eine effektive Strategie zur Priorisierung von Patches zu untersuchen und zu bestimmen. 

Risikonachweise, NVD-Zusammenfassung, Betroffene Produkte und wichtige Links

For CVEs, the Vulnerability card includes the latest information about the CVE published by NIST NVD. This includes the text summary of the vulnerability, the set of affected products in the CPE (Common Platform Enumeration), and notable links as identified by NVD. Affected Products are shown with human-readable names, and you can click on any Product Identifier to see the corresponding CPE identifier and CPE well-formed name.

mceclip1.png
  

It is common for a very recently disclosed vulnerability to include partial information, while NVD is vetting and confirming portions of the disclosure.

Zusammenfassung der National Venerability Database:

mceclip4.png
  

Zeitleisten

Vulnerability Cards may show two timelines. The first timeline, colored in blue, summarizes all reported events involving this entity in the last 60 days. The second timeline summarizes reported Cyber Attack and Cyber Exploit events specifically. Each day in the cyber event timeline is color-coded by the criticality of the Cyber Threat signal for this entity on that date.

mceclip5.png
  

Externe Links

This section includes links to pages with more information about the vulnerability, specifically around patches and remediations. 

mceclip6.png
  

Aktuelle Referenz

Hilfreiche Suche nach aktuellen Referenzen im Dark Web für diese Sicherheitsanfälligkeit.

mceclip7.png