Software vulnerabilities
eAuditor Cloud analyzes information about detected software and compares products and their versions with information about publicly known vulnerabilities.
This feature helps identify applications that may require an update, removal, or additional verification.
The detection of a vulnerability does not automatically mean the computer has been attacked. It indicates that the detected program version has been linked to a known vulnerability.
Where can vulnerabilities be found?
Go to:
IT Infrastructure > Software > Details
The information is located in the column Detected vulnerabilities.

If vulnerabilities are found for the detected product and its version, their identifiers will appear in the table.
No entries may mean that:
no known vulnerability was found for the detected version,
the program version was not identified unambiguously,
the software information is incomplete,
the vulnerability is not yet available in the sources used.
The absence of detected vulnerabilities is not confirmation that the application is secure. The result depends on correct identification of the product and version, as well as on the scope of data available in external databases.
Vulnerability details
After selecting a vulnerability identifier, the system displays the available information, such as:
vulnerability description,
CVE identifier,
EUVD identifier,
CVSS score,
EPSS indicator,
the product and version to which the entry applies,
publication or update date,
links to external sources.

The scope of data may vary for individual vulnerabilities. It depends on the information provided by the source.
How should CVSS be interpreted?
CVSS - Common Vulnerability Scoring System defines the technical severity of a vulnerability on a scale from 0 to 10.
Typical interpretation of the score:
0 - no threat rating,
0,1-3,9 - low,
4,0-6,9 - medium,
7,0-8,9 - high,
9,0-10,0 - critical.
The higher the score, the greater the potential impact of exploiting the vulnerability may be.
How should EPSS be interpreted?
EPSS - Exploit Prediction Scoring System helps assess the likelihood of a vulnerability being exploited in real-world attacks.
In simplified terms:
a low EPSS indicates a lower likelihood of exploitation,
a high EPSS indicates a higher likelihood of exploitation.
CVSS and EPSS should be analyzed together:
a high CVSS and a high EPSS usually require urgent verification,
a high CVSS and a low EPSS may still indicate significant risk, especially for a critical system,
a lower CVSS and a high EPSS may require a quick response if the vulnerability is actively exploited or affects many devices.
The final priority should also be influenced by:
the number of computers with the vulnerable version,
the importance of the devices to the organization,
internet accessibility of the system,
existing security controls,
availability of a patch or newer version,
the impact of the update on application operation.
Recommended procedure
External sources
The vulnerability details may include links to:
the NVD database,
vendor entries,
CVE or EUVD databases,
security bulletins,
update information.
Before taking action, it is advisable to confirm the vulnerability in the vendor's source, especially when an update may affect the production system.
Frequently asked questions
Last updated
Was this helpful?
