View Findings Details
Required User Role: Read-Only, Basic User, Scan Operator, Standard User, Scan Manager, or Administrator
On the Findings page, click a finding to open a pane of details. The slideout URL follows the pattern /explore/findings/findingId/repositoryId/details.
The header of the details pane contains the following information.
|
Attribute |
Description |
|---|---|
|
Plugin Name |
The name of the plugin that identified the vulnerability, for example Microsoft Netlogon Elevation of Privilege (Zerologon) (Remote). |
|
Finding ID |
The unique identifier (vulnUUID) for the finding. |
|
Tenable Nessus Plugin ID |
The numeric ID of the Tenable Nessus plugin. Links to the plugin page at tenable.com/plugins. |
|
Severity |
The vulnerability's CVSS-based severity (Critical, High, Medium, Low, Info). |
|
Exploitability |
Badges indicating exploitability characteristics, for example Remotely Exploitable, Locally Exploitable, Easy to Use, Functional, Proof of Concept, Exploited by Malware, Canvas, In the News. |
|
VPR |
The vulnerability's Vulnerability Priority Rating score. |
|
CVSS v3 |
The CVSSv3 base score for the vulnerability. |
|
ACR (Requires Tenable Security Center+) |
The Asset Criticality Rating for the asset. |
The lower part of the Findings Details page is divided into two tabs: Details and Asset Summary.
Details
The Details tab contains the following sections, in order.
|
Section |
Description |
|---|---|
| Description | A description of the vulnerability. Includes a copy-to-clipboard control. |
| Plugin Output | Output from the plugin that identified the vulnerability. |
|
Vulnerability Information |
Important information about the vulnerability, including the following attributes:
|
| Fixes |
If available, details about fixes for the vulnerability, including:
|
| Vulnerability Detection Timeline |
Information about when the vulnerability was detected, including:
|
| VPR Key Drivers |
Information about the key drivers Tenable uses to calculate a VPR for the vulnerability, including, but not limited to:
|
| Plugin Details |
Information about the plugin that detected the vulnerability, including:
|
| CVEs | Per-CVE rows showing VPR, CVSS v2/v3/v4, EPSS, and EPSS percentile. Each row includes a link to the Tenable Security Center Director CVE search page for the CVE. |
| Risk Information |
Information about the vulnerability's risk profile, including:
|
Asset Summary
The Asset Summary tab contains details about the asset associated with the finding.
|
Section |
Description |
|---|---|
| Asset Information |
Information about the affected asset, including:
Includes an Open in Assets link that pivots to /explore/assets filtered by Asset ID and Repository ID. |
| Asset Tags | Asset Tags applied to the asset. |
|
Last Seen |
Information about when the affected asset was last identified on a scan, including:
|