You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<pclass="admonition-title"><abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> - <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr> - Technical Impact</p>
2224
2224
<ol>
2225
2225
<li>A <abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> may have zero or more CWEs associated with it e.g. Log4Shell <abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr>-2021-44228 has 4 CWEs</li>
2226
-
<li>A <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr> may have zero or more Common Consequences/Technical Impacts associated with it e.g. Log4Shell <abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr>-2021-44228 has 2</li>
2226
+
<li>A <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr> may have zero or more Common Consequences/Technical Impacts associated with it e.g. <ahref="#risk-log4shell-mitre-cwe-917">Log4Shell <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr>-917</a> has 2.</li>
2227
2227
<li>A <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr> may be associated with zero or more CVEs.</li>
2228
2228
</ol>
2229
2229
<p>To understand MITRE <ahref="https://capec.mitre.org/">CAPEC</a> vs MITRE <ahref="https://attack.mitre.org/">ATT&CK</a>, see <ahref="https://capec.mitre.org/about/attack_comparison.html">https://capec.mitre.org/about/attack_comparison.html</a>.</p>
<li><ahref="https://cwe.mitre.org/">“<abbrtitle="CWE Common Weakness Enumeration">CWE</abbr></a> is the root mistake, which can lead to a vulnerability (tracked by <ahref="https://cve.mitre.org/"><abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr></a> in some cases when known), which can be exploited by an attacker (using techniques covered by <ahref="https://capec.mitre.org/">CAPEC</a>)”, which can lead to a <strong><ahref="https://capec.mitre.org/custom/view.html?id=1000">Technical Impact</a></strong> (or consequence), which can result in a <strong>Business Impact</strong></li>
2245
2245
<li><abbrtitle="National Vulnerability Database">NVD</abbr> uses <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr>-1003 (Weaknesses for Simplified Mapping of Published Vulnerabilities)</li>
2246
2246
<li>A <abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> may have zero or more CWEs associated with it e.g. Log4Shell has 4 CWEs</li>
2247
-
<li>A <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr> may have zero or more Common Consequences/Technical Impacts associated with it e.g. Log4Shell has 2</li>
2247
+
<li>A <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr> may have zero or more Common Consequences/Technical Impacts associated with it e.g. <ahref="#risk-log4shell-mitre-cwe-917">Log4Shell <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr>-917</a>has 2.</li>
2248
2248
<li>A <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr> may be associated with zero or more CVEs e.g. <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr>-917 is associated with <ahref="https://nvd.nist.gov/vuln/detail/CVE-2023-22665"><abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr>-2023-22665</a>, <ahref="https://nvd.nist.gov/vuln/detail/CVE-2023-27821"><abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr>-2023-41331</a>, <ahref="https://nvd.nist.gov/vuln/detail/CVE-2023-41331"><abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr>-2023-41331</a>, and many other CVEs.</li>
2249
2249
</ol>
2250
2250
</div></section><sectionclass="print-page" id="risk-understanding_risk"><h1id="risk-understanding_risk-understanding-risk">Understanding <abbrtitle="The likelihood of a vulnerability being exploited and the potential impact of such an exploit on an organization.">Risk</abbr><aclass="headerlink" href="#risk-understanding_risk-understanding-risk" title="Permanent link">¶</a></h1>
<td>SCA tool shows <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> score, <abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> score, and public exploits per <ahref="https://docs.mend.io/bundle/sca_user_guide/page/public_exploits_in_mend_sca.html">https://docs.mend.io/bundle/sca_user_guide/page/public_exploits_in_mend_sca.html</a></td>
4899
4899
<td></td>
4900
4900
</tr>
4901
+
<tr>
4902
+
<td><strong>Phoenix.security</strong></td>
4903
+
<td>Phoenix Security adopts a refined approach to contextual vulnerability management, integrating a sophisticated risk formula that quantifies vulnerabilities on a scale from 0 to 1000. This method encompasses three principal components: base severity, the weighted likelihood of exploitation, and the weighted business impact at the vulnerability level. <br><strong>Base Severity</strong>: Establishes the inherent risk posed by a vulnerability, serving as the foundational risk assessment metric. <br><strong>Weighted Likelihood of Exploitation</strong>: This factor evaluates the probability of a vulnerability being exploited, incorporating contextual elements such as externability, cyber threat intelligence (with the Exploit Prediction Scoring System <abbrtitle="Exploit Prediction Scoring System">EPSS</abbr> among the key indicators), <abbrtitle="Cybersecurity & Infrastructure Security Agency">CISA</abbr> Known Exploited Vulnerabilities (<abbrtitle="Known Exploited Vulnerability">KEV</abbr>), exploit availability, and exploit maturity levels (Proof of Concept, Exploitable, Weaponizable). <br><strong>Weighted Business Impact</strong>: Assesses the potential impact of a vulnerability on business operations, factoring in both a user-assigned impact score (1-10 scale) and financial implications. This dimension does not directly influence the overall risk score through financial impact but provides a comprehensive view of the potential operational disruption. Vulnerabilities are systematically categorized across assets, applications, and environments, enhancing the precision of risk assessment. The likelihood of exploitation is detailed by combining external vulnerability data, threat intelligence, and the presence and maturity of exploits. Business impact evaluation includes user input and financial impact assessments, albeit without affecting the overall risk score.\<abbrtitle="The likelihood of a vulnerability being exploited and the potential impact of such an exploit on an organization.">Risk</abbr> aggregation considers asset criticality, whether an asset is internal or external, the volume of vulnerabilities, and groups them in ranges for effective prioritization and management. <br><br>This structured approach enables Phoenix Security to deliver a nuanced, actionable framework for addressing vulnerabilities in a targeted manner.Details on the risk formula are available here: <ahref="https://phoenix.security/phoenix-security-act-on-risk-calculation/">https://phoenix.security/phoenix-security-act-on-risk-calculation/</a> For FAQ: <ahref="https://phoenix.security/faqs/">https://phoenix.security/faqs/</a> .</td>
Copy file name to clipboardExpand all lines: risk/Vulnerability_Landscape/index.html
+2-2Lines changed: 2 additions & 2 deletions
Original file line number
Diff line number
Diff line change
@@ -1547,7 +1547,7 @@ <h2 id="key-risk-factor-standards">Key <abbr title="The likelihood of a vulnerab
1547
1547
<pclass="admonition-title"><abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> - <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr> - Technical Impact</p>
1548
1548
<ol>
1549
1549
<li>A <abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> may have zero or more CWEs associated with it e.g. Log4Shell <abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr>-2021-44228 has 4 CWEs</li>
1550
-
<li>A <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr> may have zero or more Common Consequences/Technical Impacts associated with it e.g. Log4Shell <abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr>-2021-44228 has 2</li>
1550
+
<li>A <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr> may have zero or more Common Consequences/Technical Impacts associated with it e.g. <ahref="../Log4Shell/#mitre-cwe-917">Log4Shell<abbrtitle="CWE Common Weakness Enumeration">CWE</abbr>-917</a> has 2.</li>
1551
1551
<li>A <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr> may be associated with zero or more CVEs.</li>
1552
1552
</ol>
1553
1553
<p>To understand MITRE <ahref="https://capec.mitre.org/">CAPEC</a> vs MITRE <ahref="https://attack.mitre.org/">ATT&CK</a>, see <ahref="https://capec.mitre.org/about/attack_comparison.html">https://capec.mitre.org/about/attack_comparison.html</a>.</p>
@@ -1568,7 +1568,7 @@ <h2 id="key-risk-factor-standards">Key <abbr title="The likelihood of a vulnerab
1568
1568
<li><ahref="https://cwe.mitre.org/">“<abbrtitle="CWE Common Weakness Enumeration">CWE</abbr></a> is the root mistake, which can lead to a vulnerability (tracked by <ahref="https://cve.mitre.org/"><abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr></a> in some cases when known), which can be exploited by an attacker (using techniques covered by <ahref="https://capec.mitre.org/">CAPEC</a>)”, which can lead to a <strong><ahref="https://capec.mitre.org/custom/view.html?id=1000">Technical Impact</a></strong> (or consequence), which can result in a <strong>Business Impact</strong></li>
1569
1569
<li><abbrtitle="National Vulnerability Database">NVD</abbr> uses <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr>-1003 (Weaknesses for Simplified Mapping of Published Vulnerabilities)</li>
1570
1570
<li>A <abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> may have zero or more CWEs associated with it e.g. Log4Shell has 4 CWEs</li>
1571
-
<li>A <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr> may have zero or more Common Consequences/Technical Impacts associated with it e.g. Log4Shellhas 2</li>
1571
+
<li>A <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr> may have zero or more Common Consequences/Technical Impacts associated with it e.g. <ahref="../Log4Shell/#mitre-cwe-917">Log4Shell <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr>-917</a>has 2.</li>
1572
1572
<li>A <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr> may be associated with zero or more CVEs e.g. <abbrtitle="CWE Common Weakness Enumeration">CWE</abbr>-917 is associated with <ahref="https://nvd.nist.gov/vuln/detail/CVE-2023-22665"><abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr>-2023-22665</a>, <ahref="https://nvd.nist.gov/vuln/detail/CVE-2023-27821"><abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr>-2023-41331</a>, <ahref="https://nvd.nist.gov/vuln/detail/CVE-2023-41331"><abbrtitle="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr>-2023-41331</a>, and many other CVEs.</li>
0 commit comments