DAY 2 · MODULE 5
Vulnerability Assessment
Connect assets and versions to known weaknesses, severity and remediation.
Understand the concept
Vulnerability
CVE
CWE
CVSS
Patch
Misconfiguration
Severity
Remediation
Retesting
Why this matters
A useful assessment explains evidence, impact and a fix instead of only listing vulnerability names.
See what happens internally
Interactive visualization loads here.
Perform the activity
- Review a supplied service/version list.
- Match it to a prepared vulnerability reference set.
- Assign severity based on provided data.
- Write a remediation and retest note.
Workshop safety: Activities involving scanning, web vulnerabilities or security testing must be performed only on the assigned training target or intentionally vulnerable lab.
Read and understand the working example
Finding structure:
Evidence -> Risk -> Impact -> Fix -> RetestThis example is shown for guided learning. Real host/network execution is reserved for the isolated cyber-range stage.
Prove your understanding
Prepare a finding containing title, evidence, risk, remediation and retest plan.