Objectives
Use multiple helpful sources to further investigate vulnerabilities.
- Part 1: Investigate Common Vulnerabilities and Exposures (CVEs)
- Part 2: Investigate National Institute of Standards and Technology (NIST) Vulnerability Resources
- Part 3: Explore Common Weakness Enumerations (CWEs)
- Part 4: Research Vulnerabilities in the Common Vulnerability Scoring System (CVSS)
Background / Scenario
In a previous activity, you found several vulnerabilities after scanning a target system. You will now use several widely available sources to dig deeper into the details of the vulnerabilities. You will map and investigate the vulnerabilities to the Common Vulnerabilities and Exposures (CVE) list, the Common Weakness Enumeration (CWE), the NIST National Vulnerability Database, and the Common Vulnerability Scoring System (CVSS).
In this activity, you will investigate a vulnerability using different types of sources.
Required Resources
- Computer with internet connection
Instructions
Part 1: Investigate Common Vulnerabilities and Exposures (CVEs)
Step 1: Explore CVE.
- Launch the CVE website and navigate to www.cve.org.
- Read the overview of the CVE program.
- Select About > Overview in the menu.
- View the CVE Program Overview video.
- Review the available Podcasts for more detailed information about the CVE program.
Step 2: Use the CVE program to gather information about vulnerabilities.
In an earlier activity, you scanned a target system for vulnerabilities and found a few CVE that are related to SSH. SSH can be implemented in operational technology environments using the industry’s recommended practices.
One of the SSH vulnerabilities found in a previous lab was CVE-2020-15778 when running the nmap command against the gravemind.vm in the customized Kali VM.
Using the CVE website (www.cve.org), answer the following questions to learn more about this vulnerability. This vulnerability is just used as an example throughout this activity.
Enter CVE-2020-15778 into the search window and click Search.
Part 2: Investigate National Institute of Standards and Technology (NIST) Vulnerability Resources
Step 1: Explore NIST.
- Launch the NIST website by navigating to https://www.nist.gov.
- Select About NIST > About Us in the menu and review the overview of NIST.
- Explore the National Vulnerability Database (NVD).
- Return to the NIST home page and select What We Do > All Topics > Information Technology in the menu.
- Select National Vulnerability Database on the left panel.
- Click General to view and review General Information about the NVD.
- Expand the menu under General and click NVD Dashboard.
- Navigate back to the National Vulnerability Database page https://nvd.nist.gov/.
- Click Vulnerability Metrics in the menu on the left of the page.
Step 2: Use NIST database to gather more information.
- Click NVD MENU > SEARCH > Vulnerabilities – CVE to navigate to the search the vulnerability database. (https://nvd.nist.gov/vuln/search)
- Enter CVE-2020-15778 in the Keyword Search field and click Search to continue.
- Click CVE-2020-15778 to view more information about this vulnerability.
- Scroll down to the Weakness Enumeration heading.
Part 3: Explore Common Weakness Enumeration (CWE)
Step 1: Explore CWE.
- Launch the CWE website and navigate to https://cwe.mitre.org.
- Explore the CVE program.by selecting About > Overview in the menu.
Step 2: Review CWE-ID.
In this step, you will look up the CWD IDs you recorded from the previous part.
- Enter 78 in the ID Lookup box on the top right of the CWE page. (This is the CWE ID for CVE-2020-15778.)
- Scroll through the available information about this CWE.
Part 4: Research Vulnerabilities in the Common Vulnerability Scoring System (CVSS)
Step 1: Explore CVSS.
- Launch the CVSS website and navigate to https://first.org/cvss.
- Review the information on the CVSS.
- Investigate CVSS ratings by clicking Specification Document in the left menu.
- Click Examples in the left menu.
- Click the link for CVSS version 3.1 examples.
- Scroll down the page and review the example CVEs and how their CVSS v3.1 Base Scores were calculated.
- Observe the Values given for each metric that makes up the CVSS score.
Step 2: Research CVSS ratings for a vulnerability.
In this step, you will research the CVSS ratings of the CVE-2020-15778 for this activity.
- Navigate back to the National Vulnerability Database page https://nvd.nist.gov/vuln/search and search for CVE-2020-15778 and click Search. Select the desired CVE as needed on the results page.
- Scroll to the bottom of the page and click CVE-2020-15778 to view additional information on the NVD. This opens the National Vulnerability Database to view details about the CVE.
- Scroll to the Metric section and ensure that CVSS Version 3.x is selected. Observe the values for the eight CVSS Base metrics in the Vector. The corresponding numerical score of these values combine to give a base score of 7.0 HIGH.
- In a separate browser window, navigate to the CVSS 3.1 Calculator at https://www.first.org/cvss/calculator/3.1.
- In the Base Score calculator, click the metric names that correspond to the Vector on the NVD page. (Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)