Vulnerabilities
Vulnerabilities in ACE represent security weaknesses or flaws identified within your environment. Each vulnerability is associated with a specific asset and can have corresponding mitigations to address the risk.
Vulnerabilities can be of the following risk levels:
- Info
- Low
- Medium
- High
- Critical
Vulnerabilities are often tied to taxonomies in the MITRE ATT&CK framework, such as CVE, CWE, CAPEC, Tactics, and Techniques. These links are used to infer potential mitigations and followup avenues.
Viewing Vulnerabilities
Vulnerabilities can be viewed from the Security Dashboard for an environment, in the Vulnerability Table. One can see this table also at the dedicated Vulnerabilities Table page. Clicking on a specific vulnerability will provide detailed information about that vulnerability, including its associated asset, risk level, and available mitigations. One can then click on the provided ID to go the details page.
Details
The Vulnerability Details page provides a comprehensive overview of the specific vulnerability. This includes a CVSS score, category, severity, remediation status, time, and evidence submitted, as well as a statistical summary of associated connections, such as CWEs and mitigations. Users can see the Lifecycle status of the vulnerability, and admins can update the status. Below are several tabs: Mitigations, References, Threat Mapping, and Additional JSON Info.
Mitigations
The Mitigations tab lists the mitigations available for the specific vulnerability, inferred from connected Threat Mappings and additional AI suggestions. The user is told if these are created or not. Clicking on one will navigate them to the Asset Mitigation creation form.
For more information on Mitigations, refer to the Mitigations documentation.
References
The References tab provides a list of external references related to the specific vulnerability. These references can include CVE entries, security advisories, vendor documentation, and other relevant resources. Clicking on a reference will typically open the corresponding external resource for further information.
Threat Mapping
The Threat Mapping tab displays the connections between the specific vulnerability and the MITRE ATT&CK framework. This helps users understand the potential tactics and techniques associated with the vulnerability and guides the selection of appropriate mitigations.
Additional JSON Info
The Additional JSON Info tab provides a raw JSON view of the vulnerability's data. This is usually the raw slice of data used in the scan ingestion parser to infer the existence of the vulnerability.
