- August 3, 2023: Added slug names.
- May 16, 2023: Added criteria for each certainty level.
- April 28, 2023: Published.
The level of certainty that a vulnerability has been confirmed to exist and poses a risk.
Level | Description | Slug Name |
---|---|---|
Confirmed Exposure | Our scans detect that the company is using a product and can identify its version number. This version is vulnerable to a CVE. | CONFIRMED_EXPOSURE |
Suspected Exposure | Our scans detect that the company is using a product, but we may not be able to see its version number to confirm exposure. Some products can be remediated without changing their version number; in these cases, we can’t tell if the product is truly susceptible, and the exposure is marked as suspected. | SUSPECTED_EXPOSURE |
Suspected Mitigation | Our scans no longer detect publicly-facing assets with exposure to this CVE. | SUSPECTED_MITIGATION |