Software Secure Workload
Activity Configure

Vulnerability Security Score

Vulnerabilities in software packages installed on workloads are used for computing Vulnerability Security Score.

Vulnerability Security Score Details
Figure 1: Vulnerability Security Score Details

Lower score indicates:

  • One or more installed software packages have serious vulnerabilities.

  • Apply patch or upgrade to reduce the chances of exposures or exploits

Software packages on workloads could potentially be associated with known vulnerabilities ( CVE). CVSS (Common Vulnerability Scoring System) is used for assessing the impact of a CVE. CVSS score range is 0–10, with 10 being the most severe.

CVE can have CVSS v2 and CVSS v3 score. To compute Vulnerability score, CVSS v3 is considered if available, else CVSS v2 is considered.

Vulnerability score for a workload is derived from scores of vulnerable software that is detected on that workload. The Workload Vulnerability Score is calculated based on the CVSS scores, the vendor data, and may be adjusted by our security research team when data is missing or inaccurate (common for new vulnerabilities). This data is updated every 24 hours when the threat feed is configured. Higher the severity of the most severe vulnerability, lower is the score.

Scope score is average of workload scores in the scope. Improve the score by identifying workload or scopes with vulnerable software packages, and patch or upgrade with safer packages.

Help for Vulnerability Security Score
Figure 2: Help for Vulnerability Security Score