Skip to main content

CVEs and Remediation Assets

Understand how Hyver identifies and categorizes CVEs linked to remediation assets.

Updated over 5 months ago

Overview

This article explains how CVEs (Common Vulnerabilities and Exposures) are associated with remediation assets in Hyver.
CVEs are categorized by exploitability, helping you focus on assets that pose a real threat and prioritize mitigation where it matters most.


CVE categorization for remediation assets

In Hyver, each remediation asset is evaluated for known CVEs. The Has CVEs column shows one of the following values:

  • Exploitable – The asset has one or more CVEs that are considered exploitable

  • Yes – The asset has CVEs, but they are not currently exploitable

  • No – The asset has no CVEs associated with it

  • None – CVE evaluation is not relevant for this asset


How to filter for exploitable CVEs

To isolate findings tied to remediation assets with exploitable CVEs:

  1. Go to the Findings page

  2. Use the filter panel and select the Exploitable option under the Has CVEs filter:

This helps prioritize remediation efforts for assets with real exploitation potential.


Where to find CVE details

  • When you expand a finding and select a remediation asset in the right pane:

    • The Overview tab displays a list of the associated exploitable CVEs

    • Each CVE entry includes description and context:


Tracking CVE changes

  • Any changes to the Has CVEs status of a remediation asset are logged in the History tab
    This provides an audit trail of when and how CVE statuses were updated.


Wrap-up / Next Steps

Not all vulnerabilities are equal. Use CVE exploitability filters to focus on what’s actually dangerous — and track all changes as you go.

Did this answer your question?