My Findings

In the My Findings and Affected Assets section, the My Findings tab shows all active, new, or resurfaced findings for that initiative. Refine the results with the Query Builder.

The My Findings tab has the following columns, which you can show or hide as described in Customize Tables.

Column

Description

VPR

The Tenable-calculated Vulnerability Priority Rating (VPR) score from 0.1 to 10.

Note: A finding's VPR is based on the VPR of the plugin that identified it. When plugins are associated with multiple vulnerabilities, the highest VPR appears.

Plugin Name

Indicates the name of the Tenable plugin that detected the finding.

Plugin ID

Indicates the ID of the Tenable plugin that detected the finding.

Affected Assets

Indicates the number of affected assets. Click the number to open the Asset Details page.

CVEs Indicates the Common Vulnerability and Exposure (CVE) identifier for the finding, as assigned by the CISA-sponsored CVE Program.
CVSSv2 Indicates the Common Vulnerability Scoring System (CVSS) v2 score for the finding.

CVSSv3

Indicates the Common Vulnerability Scoring System (CVSS) v3 score for the finding.

Affected Assets

In any findings row, click the drop-down > to reveal a table of assets on which that finding appears, with the following columns.

Column

Description

Asset Name

The asset identifier, assigned based on the availability of specific attributes in logical order.

Operating System Indicates the operating system run on the asset, for example Linux Kernel 3.13.

IPv4 Address

Indicates the IPv4 address for the asset.

IPv6 Address

Indicates the IPv6 address for the asset.

Findings Count Indicates the number of findings on the asset. Click the number to view details on the Findings workbench.

ACR

(Requires Tenable One or Tenable Lumin license) The Tenable-defined Asset Criticality Rating (ACR) as an integer from 1 to 10.

AES

(Requires Tenable One or Tenable Lumin license) The Tenable-defined Asset Exposure Score as an integer from 0 to 1000.

Last Seen

Indicates the date when the asset last appeared on a scan.

Source Indicates the scanner or sensor that identified the finding, for example Nessus network-based assessment.

Tags

Lists any asset tags you applied in Tenable Vulnerability Management.