Incomplete Lab – Investigate Vulnerability Information Sources

Objectives

Use multiple helpful sources to further investigate vulnerabilities.

  • Part 1: Investigate Common Vulnerabilities and Exposures (CVEs)
  • Part 2: Investigate National Institute of Standards and Technology (NIST) Vulnerability Resources
  • Part 3: Explore Common Weakness Enumerations (CWEs)
  • Part 4: Research Vulnerabilities in the Common Vulnerability Scoring System (CVSS)

Background / Scenario

In a previous activity, you found several vulnerabilities after scanning a target system. You will now use several widely available sources to dig deeper into the details of the vulnerabilities. You will map and investigate the vulnerabilities to the Common Vulnerabilities and Exposures (CVE) list, the Common Weakness Enumeration (CWE), the NIST National Vulnerability Database, and the Common Vulnerability Scoring System (CVSS).

In this activity, you will investigate a vulnerability using different types of sources.

Required Resources

  • Computer with internet connection

Instructions

Part 1: Investigate Common Vulnerabilities and Exposures (CVEs)

Step 1: Explore CVE.

  1. Launch the CVE website and navigate to www.cve.org.
  2. Read the overview of the CVE program.
    1. Select About > Overview in the menu.
    2. View the CVE Program Overview video.
    3. Review the available Podcasts for more detailed information about the CVE program.
What is the mission of the CVE program?
Answer Area
To identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.
Who assigns CVE IDs?
Answer Area
The CVE Numbering Authorities (CNAs)
What are the two main goals of the CVE Program?
Answer Area
To scale the program for broader adoption and coverage and to produce more CVE records faster (closer to real time).
Who operates the CVE?
Answer Area
MITRE Corporation with funding from the US Department of Homeland Security (DHS) and the Cybersecurity and Infrastructure Security Agency (CISA) Vulnerability Management Component (VMC).

Step 2: Use the CVE program to gather information about vulnerabilities.

In an earlier activity, you scanned a target system for vulnerabilities and found a few CVE that are related to SSH. SSH can be implemented in operational technology environments using the industry’s recommended practices.

Best Practice Description
Zero Trust Access Always verify users and devices
Temporary Credentials No permanent passwords or keys
Use one-time access codes only
Identity Management System Ability to update user access based on job roles
Monitor and log SSH sessions Keep records of SSH activity for audits and detect any problems or misuse
Avoid VPN if possible Use secure, passwordless access methods, such as biometric authentication, single sign-on (SSO), and multi-factor authentication (MFA)

One of the SSH vulnerabilities found in a previous lab was CVE-2020-15778 when running the nmap command against the gravemind.vm in the customized Kali VM.

Using the CVE website (www.cve.org), answer the following questions to learn more about this vulnerability. This vulnerability is just used as an example throughout this activity.

Enter CVE-2020-15778 into the search window and click Search.

What versions of OpenSSH are subject to this vulnerability?
Answer Area
OpenSSH Versions through 8.3p1
When was this CVE last updated?
Answer Area
April 04, 2024

Part 2: Investigate National Institute of Standards and Technology (NIST) Vulnerability Resources

Step 1: Explore NIST.

  1. Launch the NIST website by navigating to https://www.nist.gov.
  2. Select About NIST > About Us in the menu and review the overview of NIST.
What is the mission of NIST?
Answer Area
“To promote US innovation and industrial competitiveness through the advancement of science, standards, and technology to enhance economic security and improve quality of life.”
  1. Explore the National Vulnerability Database (NVD).
    1. Return to the NIST home page and select What We Do > All Topics > Information Technology in the menu.
    2. Select National Vulnerability Database on the left panel.
    3. Click General to view and review General Information about the NVD.
What is the relationship between the NVD and CVEs?
Answer Area
The NVD performs analysis on CVEs that are published in the CVE dictionary. NVD staff analyze CVEs and provide additional details.
    1. Expand the menu under General and click NVD Dashboard.
How many CVE Vulnerabilities are contained in the NVD?
Answer Area
Answers will vary. At the time of this writing - 301591
What is the most recent scored Vulnerability and what is the CVSS rating?
Answer Area
Answers will vary but at time of writing – CVE-2025-7212 with CVSS Severity v3.1 of 8.8 HIGH.
    1. Navigate back to the National Vulnerability Database page https://nvd.nist.gov/.
    2. Click Vulnerability Metrics in the menu on the left of the page.
What method is used to qualitatively measure the severity of vulnerabilities?
Answer Area
The Common Vulnerability Scoring System (CVSS)
How many severity ratings does CVSS v3.0 have and what are they?
Answer Area
Five. They are: None, Low, Medium, High, and Critical.

Step 2: Use NIST database to gather more information.

  1. Click NVD MENU > SEARCH > Vulnerabilities – CVE to navigate to the search the vulnerability database. (https://nvd.nist.gov/vuln/search)
  2. Enter CVE-2020-15778 in the Keyword Search field and click Search to continue.
  3. Click CVE-2020-15778 to view more information about this vulnerability.
What is the CVSS version 3.x rating for this vulnerability?
Answer Area
CVE-2020-15778 has a CVSS version 3.x base score of 7.8 HIGH.
  1. Scroll down to the Weakness Enumeration heading.
What is the CWE-ID?
Answer Area
CVE-2020-15778 has CWE-ID 78.

Part 3: Explore Common Weakness Enumeration (CWE)

Step 1: Explore CWE.

  1. Launch the CWE website and navigate to https://cwe.mitre.org.
  2. Explore the CVE program.by selecting About > Overview in the menu.
What is the goal of CWE?
Answer Area
To stop vulnerabilities at the source by educating software and hardware architects, designers, programmers, and acquirers on how to eliminate common mistakes before products are delivered.
Who maintains the CWE?
Answer Area
The MITRE Corporation
What is the difference between a CVE and a CWE?
Answer Area
Answers may vary but CVEs identify specific vulnerabilities, while CWEs classify and describe types of weaknesses that may lead to vulnerabilities.

Step 2: Review CWE-ID.

In this step, you will look up the CWD IDs you recorded from the previous part.

  1. Enter 78 in the ID Lookup box on the top right of the CWE page. (This is the CWE ID for CVE-2020-15778.)
What is the title of this CWE?
Answer Area
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  1. Scroll through the available information about this CWE.

Part 4: Research Vulnerabilities in the Common Vulnerability Scoring System (CVSS)

Step 1: Explore CVSS.

  1. Launch the CVSS website and navigate to https://first.org/cvss.
  2. Review the information on the CVSS.
  3. Investigate CVSS ratings by clicking Specification Document in the left menu.
What are the three metrics that compose a CVSS rating?
Answer Area
Base metric, Temporal metric, Environmental metric, and Supplemental metric
How many metrics compose the Base Metric group of a CVSS? What are they?
Answer Area
There are eight metrics: Attack Vector (AV), Attack Complexity (AC), Attack Requirements, Privileges Required (PR), User Interaction (UI), Confidentiality Impact (C), Integrity Impact (I), Availability Impact (A), and Scope.
    1. Click Examples in the left menu.
    2. Click the link for CVSS version 3.1 examples.
    3. Scroll down the page and review the example CVEs and how their CVSS v3.1 Base Scores were calculated.
    4. Observe the Values given for each metric that makes up the CVSS score.

Step 2: Research CVSS ratings for a vulnerability.

In this step, you will research the CVSS ratings of the CVE-2020-15778 for this activity.

  1. Navigate back to the National Vulnerability Database page https://nvd.nist.gov/vuln/search and search for CVE-2020-15778 and click Search. Select the desired CVE as needed on the results page.
  2. Scroll to the bottom of the page and click CVE-2020-15778 to view additional information on the NVD. This opens the National Vulnerability Database to view details about the CVE.
  3. Scroll to the Metric section and ensure that CVSS Version 3.x is selected.
  4. Observe the values for the eight CVSS Base metrics in the Vector. The corresponding numerical score of these values combine to give a base score of 7.0 HIGH.
    1. In a separate browser window, navigate to the CVSS 3.1 Calculator at https://www.first.org/cvss/calculator/3.1.
    2. In the Base Score calculator, click the metric names that correspond to the Vector on the NVD page. (Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
What Base Score is calculated by the CVSS Calculator?
Answer Area
7.8

Reflection

What is the relationship between CVE, CWE, NVD, and CVSS?

Answer Area
CVE lists vulnerabilities that have been discovered, CWE classifies these vulnerabilities, NVD provides details, and CVSS provides severity ratings.

© 2023 - 2025 Cisco and/or its affiliates. All rights reserved. Cisco Public