/
Vulnerabilities

Vulnerabilities

You can find this module at the Global and Company levels.

This is the single spot where all the discovered problems and vulnerabilities across all categories will be displayed with sorting and filtering options. The table data will load the operating system with the most data and the Critical Severity problem group by default.


Visit our YouTube Channel for more video content: https://www.youtube.com/@connectsecure


Table of Contents


Vulnerabilities - Details

Access the Vulnerabilities from the Vulnerabilities category.

image-20250209-184055.png

Data is filtered by default to Internal Vulnerabilities, Windows OS, and Critical Severity. You can cycle between the filters to view data according to your preferences.

Internal Vulnerabilities = discovered on the assets directly from agent scanning

External Vulnerabilities = discovered on external assets from probe network scanning, external scanning, or attack surface mapper scanning.

image-20250209-184638.png

Problem Category Groups

Here are the default problem category groups that discovered problems will automatically go into.

Problem Group Name

Description / Use Case

Problem Group Name

Description / Use Case

0.85 > EPSS >= 0.90

Vulnerabilities grouped by EPSS Scoring >=85/90%

0.90 > EPSS >= 0.85

Vulnerabilities grouped by EPSS Scoring >=90/95%

0.95 > EPSS >= 0.90

Vulnerabilities grouped by EPSS Scoring >=90/95%

Antivirus Not Installed

Antivirus is not installed on the Asset

Backup Not Performed

Backup Agent is not installed on the Asset

CISA Notified Vulnerabilities

Vulnerabilities grouped by CISA classification; source CISA.GOV

Critical Vulnerabilities

Vulnerabilities grouped by severity of Critical

Database Vulnerabilities

Vulnerabilities grouped by classification of database

EPSS >= 0.95

Vulnerabilities grouped by EPSS Scoring >=95%

Firewall Misconfiguration

Vulnerabilities grouped by classification of firewall misconfigure

High Severity Vulnerabilities

Vulnerabilities grouped by severity of High

Information Disclosure

Vulnerabilities grouped by classification of information disclosure

Informational

This information captured is for information purpose

Low Severity Vulnerabilities

Vulnerabilities grouped by severity of Low

Mail Vulnerabilities

Vulnerabilities grouped by classification of e-mail

Medium Severity Vulnerabilities

Vulnerabilities grouped by severity of Medium

Operating System out of Support

The operating system has reached the End Of its Support

Remote Access Vulnerabilities

Vulnerabilities grouped by classification of remote access

Remote Login Vulnerabilities

Vulnerabilities grouped by classification of remote login

Running Services

Vulnerabilities grouped by classification of running services

SMB Vulnerabilities

Vulnerabilities related to SMB

SSL Certificate Info

SSL Certificate information

SSL/TLS Vulnerabilities

SSL/TLS-related Vulnerabilities

Web Server Fingerprint

Vulnerabilities grouped by classification of web server fingerprint

Problem Groups are how the ConnectSecure portal will automatically categorize discovered vulnerabilities.

image-20250209-185052.png

Tap the CVE-ID in the Problem Name field for the NIST/NVD source reference.

image-20250209-185446.png
image-20250209-185530.png

Use the three-dot Action menu to access the ‘Suppress’ option.

image-20250209-185728.png

You can do this in mass by selecting multiple records and tapping the Global Actions button.

image-20250209-185821.png

Use the column buttons to view the additional details.

This includes the Affected Companies, Affected Assets, Suppressed Records, and Auto Suppressed Records.

Suppressed Records = manually suppressed using a three-dot Action menu or Global Actions.

Auto Suppressed = automatically suppressed based on ‘Suppress Vulnerabilities Days' settings.

image-20250209-190151.png

The second bottom half of the screen contains a table of additional problems/vulnerabilities discovered by the scanning agents. This includes Registry and Driver-based checks.

image-20250209-201216.png

Like the above half, you can tap between the buttons to see Remediated and Suppressed records.

image-20250209-200549.png

Suppress

Use the three-dot Action menu or checkboxes with Global Action to suppress any of the records.

image-20250209-202951.png

Integration Action

This is only available at the Company level.

It is necessary to set up an integration before use. This will allow you to take any discovered vulnerability and send it through the integration as a call to action.

  • IE: Create a ticket in your PSA

  • IE: Send email to your support email distribution group

  • IE: Post a message to a Teams/Slack channel

Select the three-dot Action menu or check the box to access Global Actions, then tap the Integration Action option.

image-20250209-202318.png

You can choose one based on your configured integrations and then select an action.

image-20250209-202528.png

Complete the required fields based on the selected integration to complete.


Vulnerabilities - Toolbar Options

image-20250209-201400.png

Internal Vulnerabilities

Filters the table data to show internal vulnerabilities sourced directly from the agent data on local assets.


External Vulnerabilities

Filters the table data to show the external vulnerabilities sourced from the probe agent, network scans, or external scans.


Jobs

View the job details.

image-20250209-201802.png

Alerts

View our timeline style of System Events captured for each company. You can set an optional date filter range to target a specific date range of events.

image-20250206-143947.png

Info

Tap here to view your V4 Getting Started Info.

Getting Started In App Info


Help Link

image-20250206-144503.png

Click to access the related documentation page; this link is functional on all screens and will take you to the appropriate documentation page.


Layout Settings

Here, you can change the UI look and feel using various options, including the Theme for color, the Scheme for dark and light mode, the Layout for toolbar and module positions, and the toggle to set the table view default.

I prefer the Teal color, Light mode, and Classic layout with an asset table view.

image-20250206-150338.png

Get Support

Our support team is here to help. Use one of three options to start a support request.

  1. Email to support@connectsecure.com

  2. Login to our Freshdesk partner portal at https://cybercns.freshdesk.com


Related content