All low-, medium-, high-, and critical-severity Common Vulnerabilities and Exposures (CVEs) we discover in your domains affect your scorecard. Issue types that list CVEs are grouped by severity level, based on each CVE's Common Vulnerability Scoring System (CVSS) score.
Note: SecurityScorecard maps scores using CVSS version 3.0.
Use this article to identify, remediate, and resolve CVE-related issue types in your scorecard.
Issue types with score-impacting CVEs
Check your scorecard for the following issue types.
| Factor | Issue type | Description |
| Patching Cadence |
|
Vulnerabilities found by scanning the internet by IP |
| Patching Cadence |
|
CVEs unresolved after 45 days |
| Application Security |
|
Content management system vulnerabilities |
| Application Security |
|
Vulnerable OpenSSL 3.x versions detected on internet-facing services |
| IP Reputation |
|
Exploitation attempts detected against a known CVE affecting the company's assets |
| Network Security |
|
Exchange servers potentially exposed to the September 2022 ProxyNotShell zero-day exploit chain |
View score-impacting CVEs in SSC
To view the Findings table for any of these issue types, go to My Organization > My Scorecard > Issues and select the issue type. The table shows a row for each discovered instance of each CVE to help you investigate.
Tip: The Findings table and its .csv export list a maximum of 500 CVEs. If an issue type has more than 500 CVEs, call the API endpoint for that issue type to retrieve them all. For a full list of our API reference, see our developer portal.
How we find and flag CVEs
During our recurring scans of the entire internet, we identify exposed services running on 1,300 ports. These scans do not detect services running behind firewalls. We read each service's version from its banner, headers, or other publicly accessible application responses, then correlate the version with published vulnerability data to determine whether the service and version are vulnerable.
We also incorporate some CVE information from third-party sources.
Address CVE-related issue types
Prioritize CVEs by issue type and severity to address the highest-risk vulnerabilities first. Click a CVE in the Findings table to open its detailed entry in the National Vulnerability Database (NVD).
Use the links in the References section to find recent industry advisories, remediation solutions, possible compensating controls, and other resources.
Also, monitor the patching update feeds for products you use on your site, and apply updates as soon as they are available.
After you remediate a finding, submit it to the SecurityScorecard Support team for review.