Vulnerabilities and VEX
How vulnerabilities are assessed and prioritised, and how VEX states which ones affect a product.
- What is a vulnerability?
A vulnerability is a weakness in a system that can be exploited by attackers. This article explains what vulnerabilities are, how they are assessed with CVSS and EPSS, common types of vulnerabilities, and the importance of patch management and prioritisation based on SBOMs.
- What is VEX?
A vulnerability scan against an SBOM often returns findings that cannot be exploited in the product at hand. With VEX the supplier states a status for each vulnerability, so that the recipient can prioritise correctly.
- SBOM and vulnerability management
An SBOM makes it possible to answer which products are affected by a vulnerability. This page goes through the workflow: match against vulnerability data, prioritise with CVSS, EPSS and KEV, and filter out what does not affect you with VEX.
- What is VDR?
A VDR is the supplier's account of which vulnerabilities affect a product and its components, how they affect the product and what is being done about them. The term comes from NIST SP 800-161.