Vulnerability Assessment

Detect and prioritize known vulnerabilities to fix them before attackers exploit them.

Improve your IT hygiene with the Vulnerability Assessment feature. 

icon-40-grey-radar
Anticipate potential entry points for attackers
icon-40-grey-alert
Prioritize vulnerabilities effectively
icon-40-grey-peoplesettings
Implement corrective actions
icon-40-grey-fast
Track the impact of your actions

Vulnerability Assessment is available via both the Cloud and On-Prem versions of HarfangLab. This feature reports vulnerabilities identified on your IT infrastructure using a continuously updated list of public vulnerabilities (CVEs). 
Installation is simple and requires no specific configuration 

CVEs are continuously retrieved by the HarfangLab security platform and compared with the software and applications deployed on the protected IT environments to report vulnerabilities that need to be corrected. 

This enables security teams to stay one step ahead of threats. Immediately prioritize and remediate detected vulnerabilities, and correlate data with that of the deployed agents if needed.  

  • Continuous automatic detection without scanning
  • CVE database constantly updated
  • Daily reporting

What is a CVE?

CVE stands for Common Vulnerabilities and Exposures. It is a public database that lists IT security vulnerabilities – Log4Shell and Spectre are among the most infamous examples. 

The cyber ecosystem relies on these databases to report vulnerabilities to security teams.  

These vulnerabilities are given a standardized score that assesses their criticality, called the Common Vulnerability Scoring System (CVSS). This score ranges from 0 for the least critical to 10 for the most critical.  

This score should be considered in the context of each unique organization. A vulnerability that is not inherently critical may still affect essential devices or solutions critical to the organization. In this case, it must be remediated as quickly as possible, even if the CVSS score is low! 

Vulnerability Assessment is accessible via the HarfangLab console. 

This feature is also available as a standalone feature with the Scout offering, without EDR or EPP. 

Unlike EDR detection rules, for example, the CVEs list comes from NIST and cannot be customized 

For the Cloud and On-Prem versions of HarfangLab, the CVEs list is updated constantly and deployed to the consoles of SaaS solution users.  

For On-Prem or Air-gapped environments, the updated file is stored in a dedicated secure space and can be loaded into the console manually. 

This update frequency allows for optimal responsiveness to correct vulnerabilities wherever and whenever they occur.