My Affected Assets

In the My Findings and Affected Assets section, the My Affected Assets tab shows all assets in the initiative with a finding that has not yet been fixed. Refine the results with the Query Builder to provide business context.

The My Affected Assets tab has the following columns.

Column

Description

Name

The user-defined hostname or name of the affected asset.

Vulnerabilities

The total count of vulnerabilities detected on the asset.

CVEs

The Common Vulnerability and Exposure (CVE) identifier for the finding on the asset, as assigned by the CISA-sponsored CVE Program.

Tag

Any custom tags applied to the asset within the Tenable environment.

Asset ID

The unique internal identifier Tenable uses to track the asset.

Architecture The system architecture of the asset's operating system (for example, x86_64).
Distribution The Linux distribution or OS variant installed on the asset (for example, Ubuntu, CentOS, Windows Server).

Operating System

The name and version of the operating system running on the asset, for example Linux Kernel 3.13.

Last Scanned The date and time the asset was most recently scanned by Container Security.
Plugin Count The number of plugins impacting this image.

Plugins

In any asset row, click the drop-down > to reveal a table of plugin results for the findings on that asset, with the following columns.

Column

Description

VPR

The Vulnerability Priority Rating that Tenable calculated for the vulnerability.

Note: A finding's VPR is based on the VPR of the plugin that identified it. When plugins are associated with multiple vulnerabilities, the highest VPR appears.

Severity

The vulnerability's severity, based on the Common Vulnerability Scoring System (CVSS).

Plugin Name

The name of the Tenable plugin that detected the finding.

Plugin ID

The unique identifier for the Tenable plugin that detected the vulnerability.

Findings

The number of findings detected on the asset.

CVSSv2 The CVSSv2 score for the finding.

CVSSv3

The CVSSv3 score for the finding.