Cisco Cyber Vision New UI Administration Guide, Release 5.6.0

PDF

Cisco Cyber Vision New UI Administration Guide, Release 5.6.0

Vulnerabilities

Want to summarize with AI?

Log in

This concept explains what vulnerabilities are, how they are detected within the system, and their implications for asset security.


A vulnerability is a system weakness that

  • enables attackers to gain unauthorized access or perform malicious actions,

  • results from flaws in system design, implementation, or configuration, and

  • requires mitigation through security measures to prevent exploitation.

Feature history table

Feature

Release Information

Feature Description

Bulk vulnerability acknowledgment for assets

Release 5.5.x

You can now acknowledge or unacknowledge multiple vulnerabilities at once from the asset vulnerability table. This change removes manual processing, saving time for asset security.

Asset vulnerability insights in New UI

Release 5.5.x

Cyber Vision Center matches asset properties against the knowledge database to detect vulnerabilities. You can view the matched asset properties in the New UI. This process provides clear, actionable insights into your security posture.


Vulnerability detection in Cyber Vision Center

Cyber Vision Center detects vulnerabilities on assets by matching their properties (such as vendor, reference, and firmware version) against a knowledge database of detection rules. This database regularly receives updates from external sources such as Computer Emergency Response Teams (CERTs), device manufacturers, and leading industry partners (e.g., Schneider and Siemens).

Key attributes of vulnerability detection:

  • The vulnerability detection process is automated and relies on the latest rule database updates.

  • Viewing asset vulnerability information allows security teams to assess risk exposure and prioritize remediation efforts.

To view the asset properties used for vulnerability detection in the system:

  • From the main menu, choose Assets.

  • Select the asset with vulnerabilities.

  • Click Vulnerabilities and select the relevant vulnerability.


Vulnerability scores

Vulnerability scores indicate the potential risk level and impact associated with specific vulnerabilities. Vulnerability scores include the following scoring systems.

Cisco Security Risk Score (CSRS)

The Cisco Security Risk Score, which is powered by Cisco Vulnerability Management, is represented on a scale from 0 to 100.

CSRS quantifies the risk of a vulnerability by looking beyond technical severity to determine how real-world attackers are leveraging the vulnerability in the wild, if at all. The score considers vulnerability and threat variables, including predictive modeling to forecast the weaponization of vulnerabilities, the availability of recorded exploits or exploit kits, the presence of near real-time exploitation, and more.

A click-through product demo supports self-paced exploration of Cisco Vulnerability Management and the Cisco Security Risk Score.

Common Vulnerability Scoring System (CVSS)

The Common Vulnerability Scoring System (CVSS) captures the principal characteristics of a vulnerability and produces a numerical score that reflects its severity. The numerical score can be translated into a qualitative representation, such as low, medium, high, and critical, to help organizations assess and prioritize vulnerability management processes.

For more information, refer to the CVSS website.


Vulnerabilities details

The Vulnerabilities page lists all identified vulnerabilities and their details.
Table 1. Vulnerability field descriptions

Field name

Description

Possible values/examples

CVE ID

CVE ID stands for Common Vulnerabilities and Exposures Identifier. It is a unique, standardized identifier assigned to publicly known cybersecurity vulnerabilities. This ID allows for consistent referencing of specific vulnerabilities across different security products and databases.

CVE-2023-20198

Name

This field provides a concise, descriptive title for the vulnerability.

Out-of-bounds Write Vulnerability in Rockwell ControlLogix Communication Modules

Cisco Security Risk Score (CSRS)

This is a proprietary risk assessment score developed by Cisco. It provides an evaluation of the vulnerability's severity and potential impact based on Cisco's internal analysis and threat intelligence. It's typically presented as a numerical score along with a severity level (e.g., High, Medium, Low).

  • 67-100: High vulnerability

  • 34-66: Medium severity vulnerability

  • 0-33: Low severity vulnerability

CVSS Score

It is the industry standard for assessing the severity of computer system security vulnerabilities. It provides a numerical score (0-10) and a qualitative severity rating (Low, Medium, High, Critical) based on various metrics like attack vector, complexity, impact on confidentiality, integrity, and availability. Security teams use CVSS scores to prioritize severe vulnerabilities and strengthen system security.

  • 9-10: Critical vulnerability

  • 7-8.9: High severity vulnerability

  • 4-6.9: Medium severity vulnerability

  • 0.1-3.9: Low severity vulnerability

MITRE ATT and CK Tactics

Indicates whether the vulnerability can be associated with specific tactics from the MITRE ATT and CKĀ® framework. Tactics represent the "why" of an attack (for example, gaining initial access, privilege escalation). A technique describes the specific actions or methods an attacker uses to achieve a tactic. Each tactic may be achieved through multiple techniques.

To view detailed information about the tactics and techniques associated with a specific vulnerability, click the CVE ID link and review the MITRE ATT and CK section. The "3 Tactics matched" (for example) indicator suggests that the system has identified activities corresponding to three different MITRE ATT and CK tactics. Under each tactic, you can find one or more techniques used. For additional details, visit https://attack.mitre.org.

Execution, Exfiltration, Persistence

Attack Vector

Describes the path or means by which an attacker can exploit the vulnerability. It indicates the context from which the vulnerability can be exploited (example, locally, over a network, physically).

Network, Adjacent Network, Local, Physical

Affected Assets

This number indicates how many of your monitored assets are currently identified as being vulnerable to this specific CVE. Clicking on the CVE ID provides a detailed list of these assets.

1 for CVE-2023-20198, 2 for CVE-2024-20437


Acknowledge or unacknowledge vulnerabilities for a single asset

Enable efficient management of security alerts by acknowledging or unacknowledging vulnerabilities detected for a single asset.

Perform this task to prioritize remediation efforts and maintain an accurate security dashboard. When you acknowledge a vulnerability, its alerts are removed from the Alerts dashboard. If you revert the acknowledgement, the alerts will appear in the Alerts dashboard again.

Before you begin

Ensure you have access to the Assets and Vulnerabilities dashboards in Cyber Vision Center. You may need to check your permissions under Admin > Users > Role Management.

Procedure

  1. From the main menu, choose Assets.

  2. Select an asset.

  3. Select the Vulnerabilities tab.

  4. To view an acknowledged vulnerability in the Alerts dashboard again and revert the acknowledgement:

    1. Check the checkboxes for the vulnerabilities you want to acknowledge.

      Check all the checkboxes to select all vulnerabilities at once.

    2. Click Acknowledge.

    3. Enter a comment if needed and confirm your acknowledgement.

  5. To unacknowledge vulnerabilities:

    1. Click Show Acknowledged to see acknowledged vulnerabilities.

    2. Check the checkboxes for the vulnerabilities you want to unacknowledge.

    3. Click Unacknowledge.

  • When you acknowledge a vulnerability, the system removes the alerts for that vulnerability from the Alerts dashboard.

  • When you revert an acknowledgement, the alerts reappear in the Alerts dashboard.

What to do next

View the Alerts dashboard to verify the updated status of vulnerabilities.


Acknowledge or unacknowledge multiple assets for a single vulnerability

Simplify vulnerability management by acknowledging or unacknowledging multiple affected assets in a single operation. This reduces the time required to process vulnerability changes across several assets.

Use this task when the same vulnerability is detected across multiple devices in your environment. Bulk acknowledgment or unacknowledgment helps keep your security status accurate without repeating actions for each asset.

Procedure

  1. From the main menu, choose Vulnerabilities.

  2. Select the vulnerability you want to manage.

  3. To acknowledge assets:

    1. In the Affected tab, check the checkboxes for the assets you want to acknowledge.

    2. Add a comment to provide context for the acknowledgment.

    3. Click Acknowledge selected assets and confirm.

  4. To unacknowledge assets:

    1. In the Acknowledged tab, check the checkboxes for the assets you want to unacknowledge.

    2. Click Unacknowledge.

The system acknowledges or unacknowledges the selected assets for the specified vulnerability.

What to do next

Review the updated vulnerability list to confirm the changes.


Acknowledge critical vulnerabilities

Acknowledge critical vulnerabilities with a CVSS score greater than 9.0 to declutter dashboards, and reduce alert noise.

Use this task when you need to focus on vulnerabilities of the highest severity for an asset by filtering and acknowledging them.

Before you begin

  • Ensure you have permission to view and acknowledge vulnerabilities.

Procedure

  1. From the main menu, choose Assets and click asset name.

  2. View the Vulnerabilities list for the selected asset.

  3. Click the filter icon of the table.

  4. Select Critical from the drop-down list in the CVSS Score column.

  5. Click Acknowledge.

When you acknowledge vulnerabilities, they no longer appear in dashboard counters and alerts. This simplifies ongoing risk management.

What to do next

Review acknowledged items periodically to ensure they remain appropriate.