Skip to content

Vulnerability Management

The vulnerability module correlates known CVEs with assets using vendor, model, firmware, and configured external feeds (NVD, CISA KEV, and others when enabled).

Requires module.vulnerabilities. Tenant administrators configure scanners and feeds under Vulnerabilities → Configuration (/vulnerabilities/configuration).

RoutePurpose
/vulnerabilitiesCVE list with severity and remediation status
/vulnerabilities/by-assetRisk grouped per asset
/vulnerabilities/:idCVE detail, affected assets, notes
/vulnerabilities/configurationFeed sync, scanner settings
  1. Ensure assets have accurate vendor, model, and firmware/OS for CPE matching.
  2. Run or schedule vulnerability scans / feed sync (see CVE Management).
  3. Triage findings: assign owners, set remediation status, link to changes or incidents when fixing.
  • vulnerabilities.read — view findings
  • vulnerabilities.update — change remediation status and assignments
  • vulnerabilities.create / delete — administrative operations where exposed