Analyze CVEs requiring immediate attention in Trellix Insights

Prev Next

Trellix Insights allows you to analyze the CVEs associated with campaigns in your environment that require immediate attention and take the appropriate steps to mitigate them.

For details about product features, usage, and best practices, click ? or Help.

  1. Log on to Trellix Insights.

  2. Click Insights_megamenu_icon.png and select CVEs. The list of CVEs that requires attention are displayed under the CVEs Requiring Attention tab.

  3. (optional) Filter (GUID-B39D3406-4908-4CFC-ACFA-FBCEBBD9CF29-low.png) CVEs by CVE Published Year, Vendor name, Product name, Severity, and Resolution status. An unresolved CVE results in a lower posture score which affects the overall security posture score.

    Note

    You can also view the CVEs for specific vendors and their products by creating CVE preferences.

  4. (optional) Sort the CVE list by Number of Associated Campaigns, CVSS score, and Published Date.

  5. Select the CVE and view the following details:

    Option

    Description

    CVE ID

    Unique ID assigned to a vulnerability.

    CVE Published Date

    The date when the CVE was published.

    Description

    A brief description of the CVE.

    Vendor Name

    The name of the vendor whose product is affected by this CVE vulnerability.

    Product Name

    The name of the product affected by this CVE vulnerability.

    CVSS score

    A score that represents the severity of the vulnerability. CVSS scores are based on three categories: Base score, Temporal score, and Environmental score.

    CVSS vector

    A string value to determine the vulnerability metrics. The CVSS score is mapped to the CVSS vector.

    Impact

    The potential damage to the system if this vulnerability is exploited.

    CWE ID

    Describes the nature of software weakness that results to security vulnerabilities. For more information, see the CWE categories list.

    Exploited in the wild

    Indicates whether this vulnerability is known to and actively used by threat actors.

    Patch available

    Indicate whether the patch is available for this vulnerability.

    POC link

    The proof of concept to determine whether your environment is vulnerable.

    Detection Strategy

    Describes a set of measures and processes to detect and respond to the vulnerability.

    Remediation

    A brief description (or steps) to remediate the vulnerability.

    Associated Campaigns

    List of campaigns associated with this CVE.

    Detected Campaigns

    List of campaigns detected in your environment for this CVE.

    References

    External link to sites that provide more information about the CVE.

  6. Click Mark as complete. This improves the overall security posture score and the CVE is added to the list of CVEs for All Campaigns.