Vulnerability Assessment Flashcards
CVSS assessment consists of three metrics for measuring vulnerabilities
Base metrics: It represents the inherent qualities of a vulnerability.
Temporal metrics: It represents the features that keep on changing during the lifetime of a vulnerability.
Environmental metrics: It represents the vulnerabilities that are based on a particular environment or implementation.
This part of the report provides information such as the name of the scanning tool, its version, and the network ports that have to be scanned
Scan information
This part of the report contains information about the target system’s name and address
Target information
This section provides a complete scanning report. It contains subtopics such as target, services, vulnerability, classification, and assessment
Results
This subtopic includes each host’s detailed information
Target
The subtopic defines the network services by their names and ports.
Services
This subtopic allows the system administrator to obtain additional information about the scanning such as origin of the scan
Classification
This class provides information regarding the scanner’s assessment of the vulnerability
Assessment