View Findings Details

Required User Role: Read-Only, Basic User, Scan Operator, Standard User, Scan Manager, or Administrator

On the Findings page, click a finding to open a pane of details. The slideout URL follows the pattern /explore/findings/findingId/repositoryId/details.

The header of the details pane contains the following information.

Attribute

Description

Plugin Name

The name of the plugin that identified the vulnerability, for example Microsoft Netlogon Elevation of Privilege (Zerologon) (Remote).

Finding ID

The unique identifier (vulnUUID) for the finding.

Tenable Nessus Plugin ID

The numeric ID of the Tenable Nessus plugin. Links to the plugin page at tenable.com/plugins.

Severity

The vulnerability's CVSS-based severity (Critical, High, Medium, Low, Info).

Exploitability

Badges indicating exploitability characteristics, for example Remotely Exploitable, Locally Exploitable, Easy to Use, Functional, Proof of Concept, Exploited by Malware, Canvas, In the News.

VPR

The vulnerability's Vulnerability Priority Rating score.

CVSS v3

The CVSSv3 base score for the vulnerability.

ACR (Requires Tenable Security Center+)

The Asset Criticality Rating for the asset.

The lower part of the Findings Details page is divided into two tabs: Details and Asset Summary.

Details

The Details tab contains the following sections, in order.

Section

Description

Description A description of the vulnerability. Includes a copy-to-clipboard control.
Plugin Output Output from the plugin that identified the vulnerability.

Vulnerability Information

Important information about the vulnerability, including the following attributes:

  • Severity — The vulnerability's CVSS-based severity.

  • Vulnerability Published — The oldest date on which the vulnerability was either documented in an advisory or published in the National Vulnerability Database (NVD).

  • Exploit Available — Whether a known exploit exists.

  • Patch Published — The date a patch for the vulnerability was published.

  • Exploitability Ease — A description of how easy it is to exploit the vulnerability.

  • Exploited With — Exploit frameworks associated with the vulnerability.

  • Port — The port the scanner used to connect to the asset where the vulnerability was found.

  • Protocol — The protocol associated with the finding.

  • CPE — The Common Platform Enumeration identifier for the application.

Fixes

If available, details about fixes for the vulnerability, including:

  • Solution — A summary of how to officially remediate the vulnerability.

  • See Also — Links to websites with helpful information about the vulnerability.

Vulnerability Detection Timeline

Information about when the vulnerability was detected, including:

  • First Seen — The date when a scan first found the vulnerability on an asset.

  • Last Seen — The date when a scan last found the vulnerability on an asset.

  • Last Fixed — The date the finding was last marked as fixed.

  • Vulnerability Age — The age of a vulnerability based on its State. For Active vulnerabilities, based on the time elapsed between First Seen and today's date. For Fixed vulnerabilities, based on the time elapsed between First Seen and Last Fixed or the time elapsed between Resurfaced and Last Fixed. For Resurfaced vulnerabilities, based on the time elapsed between Resurfaced and and today's date.

VPR Key Drivers

Information about the key drivers Tenable uses to calculate a VPR for the vulnerability, including, but not limited to:

  • CVE ID — The CVE that is the primary contributor to the VPR score.

  • VPR Severity — The VPR severity categorization.

  • VPR Percentile — The score's percentile ranking relative to other vulnerabilities.

  • Exploit Code Maturity — Maturity of available exploit code. Options: High, Functional, PoC, Unproven.

  • Exploit Probability — Estimated probability of exploitation.

  • Exploit Chain — Whether the CVE is part of a known exploit chain.

  • On CISA KEV — Whether the CVE appears on the CISA Known Exploited Vulnerabilities catalog.

  • In the News Intensity (Last 30) — Volume of recent media coverage.

  • In the News Recency — Recency of media coverage.

  • In the News Sources (Last 30) — Categories of news sources referencing the CVE.

  • Malware Observations Intensity (Last 30) — Volume of malware observations.

  • Malware Observations Recency — Recency of malware observations.

  • Targeted Industries — Industries where attacks leveraging this CVE have been observed.

  • Targeted Regions — Geographic regions where attacks have been observed.

Plugin Details

Information about the plugin that detected the vulnerability, including:

  • Plugin Family — The family of the plugin that identified the vulnerability.

  • Plugin Type — The general type of plugin check (for example, local or remote).

  • Plugin Publish Date — The date on which the plugin that identified the vulnerability was published.

  • Plugin Updated — The date on which the plugin was last modified.

  • Version — The version of the plugin that identified the vulnerability.

CVEs Per-CVE rows showing VPR, CVSS v2/v3/v4, EPSS, and EPSS percentile. Each row includes a link to the Tenable Security Center Director CVE search page for the CVE.
Risk Information

Information about the vulnerability's risk profile, including:

  • CVSS v2 Severity (Risk Factor) — The CVSS-based risk factor associated with the plugin.

  • CVSSv2 Base Score — The CVSSv2 base score (intrinsic and fundamental characteristics of a vulnerability that are constant over time and user environments).

  • CVSSv3 Base Score — The CVSSv3 base score (intrinsic and fundamental characteristics of a vulnerability that are constant over time and user environments).

  • CVSSv3 Vector — A CVSSv3-based text string containing metric:value pairs to describe vulnerability characteristics, for example AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

  • CVSSv4 Base Score — The CVSSv4 base score (intrinsic and fundamental characteristics of a vulnerability that are constant over time and user environments).

  • CVSSv4 Vector — A CVSSv4-based text string containing metric:value pairs to describe vulnerability characteristics, for example AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

  • Plugin Publish Date — The date the plugin was published.

  • Version — The plugin version.

Asset Summary

The Asset Summary tab contains details about the asset associated with the finding.

Section

Description

Asset Information

Information about the affected asset, including:

  • Asset Name — The name of the asset where a scan detected the vulnerability. This value is unique to Tenable One Vulnerability Management.

  • IP Addresses — The IPv4 address(es) for the affected asset.

  • Asset ID — The UUID of the asset where a scan detected the vulnerability.

  • Operating System — The operating system that the scan identified on the affected asset.

  • DNS Name — The fully qualified domain name of the asset host.

  • MAC Addresses — The MAC addresses for the affected asset.

  • NetBIOS — The NetBIOS name of the asset.

  • Repository — The repository that contains this finding.

  • OS CPE — The CPE identifier for the operating system.

  • ACR — The Asset Criticality Rating. Includes an Edit option if you have a Tenable Security Center+ license.

  • ACR Source — The source of the ACR value.

  • Key Drivers — The factors contributing to the ACR score.

Includes an Open in Assets link that pivots to /explore/assets filtered by Asset ID and Repository ID.

Asset Tags Asset Tags applied to the asset.

Last Seen

Information about when the affected asset was last identified on a scan, including:

  • First Seen — The date when a scan first found the vulnerability on an asset.

  • Last Seen — The date when a scan last found the vulnerability on an asset.

  • Last Authenticated Scan — The date and time of the last authenticated scan run against the asset.

  • Last Unauthenticated Scan — The date and time of the last unauthenticated scan run against the asset.

  • Last Scan — The date and time of the most recent scan of any type run against the asset.

  • Scan Policy — The scan policy used in the most recent scan.

  • Source — The source of the scan that detected the vulnerability on the affected asset, for example Tenable Nessus.