Viewing Vulnerabilities in VMDR OT

The Vulnerabilities tab gives you a complete view of the vulnerability posture of the assets in your industrial network.

Consolidated view of ICS vulnerabilities

The vulnerabilities table contains the list of detected vulnerabilities and their following details:

Column Description
QID The unique Qualys ID assigned to the vulnerability. Click the QID to view the detailed vulnerability information.
Title The title of the detected vulnerability, providing a brief description of the security issue.
QDS The Qualys Detection Score that indicates the confidence and risk level of the detection. A higher QDS value signifies a greater risk.
Severity The severity level (1-5) determined by the security risk associated with the exploitation of the vulnerability. A higher value indicates a more critical vulnerability.
Last Detected The date and time when the vulnerability was most recently detected on the asset.
First Detected The date and time when the vulnerability was first detected on the asset.
Asset The asset (identified by name or IP address) on which the vulnerability is detected.
Rack/Slot The physical rack and slot location of the affected module within the industrial control system helps you identify the exact hardware component.

In the upper left corner, you see your network's total count of vulnerability detections. These are the vulnerabilities detected by Qualys Network Passive Sensor.

In the search bar, you can build QQL queries to narrow down the scope of your vulnerability search by using the supported search tokens. For more information, see Search Tokens for VMDR OT.

Right below the total detections, you see vulnerabilities grouped into various categories. After you click a category in this list, your selection gets translated into a QQL query in the search bar, and the vulnerabilities that fit into your selected category are displayed in the vulnerabilities table.

Search narrowed down to view only Confirmed vulnerabilities.

By using the date and time range selector next to the search bar, you can choose to view vulnerabilities detected within a specific time period.

Date time range picker.

Vulnerability Details Page

To view the detailed information of a vulnerability, click the QID from the Vulnerabilities tab. The Vulnerability Details page opens, displaying the following tabs:

Vulnerability Details page.

Detection SummaryDetection Summary

The Detection Summary tab provides a quick overview of the vulnerability detection on the asset. It includes:

Section Description
Vulnerability Title Displays the name of the detected vulnerability.
QID Displays the unique Qualys ID (QID) assigned to the vulnerability.
Status Displays the current detection status of the vulnerability.
QDS Displays the QDS assigned to the vulnerability detection.
Last Found Displays the date and time when the vulnerability was most recently detected on the asset.
CVE Lists the CVEs associated with the QID.
Severity Displays the severity level of the vulnerability.
Vulnerability Result Shows the detection result, including the affected device version, firmware, or configuration identified during the scan.
Vulnerability Description Provides a detailed description of the vulnerability, including the affected products and the detection logic used to identify it.
Detection Logic Provides the detection logic used to find the vulnerability.
About Asset Displays key asset information, including Asset ID, IP Address, MAC Address, Equipment Class, Equipment Type, Manufacturer, Product, Model, Firmware Version, and Rack/Slot details.

QDS DetailsQDS Details

The QDS Details tab displays the Qualys Detection Score (QDS) and its contributing factors. The QDS is calculated taking into account the CVSS score and the vulnerability context to prioritize remediation actions. This tab includes:

Section Description
QDS Gauge Displays the Qualys Detection Score (QDS) on a visual gauge ranging from 0 to 100, along with the corresponding risk level: Low (0–39), Medium (40–69), High (70–89), or Critical (90–100).
Contributing Factors Lists the factors that contribute to the QDS calculation for the selected asset, helping you understand the drivers behind the score.
Highest Contributing CVE Displays the CVE that has the greatest impact on the QDS for the selected asset.
Additional Insights Provides an expandable section with supplementary information and additional details about the QDS calculation.

General InformationGeneral Information

The General Information tab provides detailed metadata about the vulnerability. It includes:

Section Description
Identification Displays key vulnerability details, including QID, Category (ICS), Modified Date, Discovery Method (for example, REMOTE), Authentication Requirement, and Supported Apps.
CVSS Summary Displays the CVSS v2 and CVSS v3.1 Base and Temporal scores, along with the Access Vector used to assess the vulnerability.
Vendor Reference Displays the vendor-specific security advisory or reference associated with the vulnerability (for example, PN1558).
Vulnerability Analysis Summarizes the availability of Exploits, Patches, and Malware associated with the vulnerability.
Impact Describes the potential impact on the affected asset if the vulnerability is successfully exploited.
Solution Provides recommended remediation steps, including links to vendor advisories and other relevant resources.
Customized Solution Comments Displays custom remediation guidance specific to your environment. You can add or modify solution comments by navigating to VM/VMDR > KnowledgeBase and selecting Edit from the Quick Actions menu for the desired QID.

ExploitabilityExploitability

The Exploitability tab lists known exploits for the vulnerability available from third-party vendors and/or publicly available sources. The table includes:

Section Description
Source Displays the source from which the exploit information was obtained.
Reference Displays the reference identifier associated with the exploit.
Description Provides a brief description of the exploit and its associated details.

PatchesPatches

The Patches tab displays available patches to fix the vulnerability. The table includes:

Section Description
Patch Displays the name or identifier of the patch available to remediate the vulnerability.
Reference Displays the vendor reference associated with the patch (for example, PN1558).
Type Displays the type of patch provided by the vendor.
Vendor Severity Displays the severity rating assigned to the vulnerability by the vendor.

MalwareMalware

The Malware tab displays any published malware associated with the vulnerability. Here you can assess the malware family and its risk level.

CVE DetailsCVE Details

The CVE Details tab provides detailed information about all CVEs associated with the vulnerability. The following details are displayed:

Section Description
Total CVEs Displays the total number of Common Vulnerabilities and Exposures (CVEs) associated with the vulnerability.
CVE List Lists each associated CVE along with its corresponding Qualys Vulnerability Score (QVS).
Technical Attributes Displays technical details for each CVE, including CVSS Score, CISA Known Exploited Vulnerability (KEV) status, and CISA Due Date.
Temporal Attributes Displays time-sensitive threat information, including Exploit Code Maturity (ECM), Exploit Type, Malware associations, Threat Actor information, and Trending status.
Remediation Displays the Zero-Day status and remediation information for the CVE.
Published Date Displays the date on which the CVE was published.

MITRE ATT&CKMITRE ATT&CK

The MITRE ATT&CK tab maps the vulnerability to the MITRE ATT&CK framework, showing the associated tactics, techniques, and procedures (TTPs). This helps you understand how the vulnerability could be leveraged by attackers in the context of industrial control system threats.

For more information on MITRE ATT&CK Tactics, refer to VMDR Online Help.

Add Customized Solution Comments

You can add Customized Solution Comments for ICS QID in the General Information tab of Vulnerability Details. This allows you to write customized solutions specific to your environment.

To add the solution comment for the vulnerability, go to VM/VMDR > KnowledgeBase and select Edit from the Quick Actions menu of the desired QID.

Go to the Solution section, and enter your Solution Comments.

Related Topics

Viewing KnowledgeBase