Vulnerability Management: CVEs, KEV, Patching and Verification
Vulnerability management is the defender loop: find weaknesses (often tracked as CVEs), prioritise what matters (CVSS plus CISA KEV and asset value), patch or mitigate, then verify the fix with evidence. Scanning alone is not a program — owned SLAs and re-checks keep Equifax-style unpatched disasters from repeating.
Friends! A CVE ID is not a Wikipedia number — a trackable flaw. KEV = CISA's "actively exploited" list — focus there first. After patch, verify: version check, re-scan, change ticket. Today defence-only lifecycle — no exploit PoC / attack-framework steps. Own lab and written authorisation only.
मित्रांनो! CVE ID Wikipedia number नाही – trackable flaw. KEV = CISA ची "actively exploited" list – आधी त्यावर focus. Patch नंतर verify: version check, re-scan, change ticket. आज defence-only lifecycle – exploit PoC / attack-framework steps नाही. Own lab आणि written authorisation only.
मित्रों! CVE ID Wikipedia number नहीं – trackable flaw. KEV = CISA की "actively exploited" list – पहले उस पर focus. Patch के बाद verify: version check, re-scan, change ticket. आज defence-only lifecycle – exploit PoC / attack-framework steps नहीं. Own lab और written authorisation only.
Quick answer
Vulnerability management in one vertical checklist:
- Inventory assets (OS, apps, cloud images, libraries).
- Discover findings (authenticated scanner, vendor advisories, dependency alerts).
- Map each finding to a CVE (and CWE when useful).
- Prioritise: KEV first, then critical CVSS on internet-facing / crown-jewel assets.
- Patch, upgrade, or apply a temporary compensating control.
- Verify: package version, config proof, clean re-scan, ticket closed with evidence.
- Report trends: open aging, mean time to remediate, KEV backlog = 0.
Tiny mental model:
Inventory → Discover → Prioritise (KEV/CVSS/asset) → Fix → Verify → Improve
Scan without owner = PDF wallpaper
Patch without verify = hope
What do I need before this guide?
- Idea of what a security update is on Windows / Linux.
- Optional: How to use nmap ethically (authorised scanning only).
- Optional: Incident response first 24 hours.
What are CVE, CVSS and KEV?
Discover CVEs, prioritise with KEV and CVSS, patch, then verify with a re-scan and ticket evidence.
CVEs discover करा, KEV आणि CVSS ने prioritise करा, patch करा, मग re-scan आणि ticket evidence सह verify करा.
CVEs discover करो, KEV और CVSS से prioritise करो, patch करो, फिर re-scan और ticket evidence के साथ verify करो.
- CVE — Common Vulnerabilities and Exposures: a public ID for a known flaw (example shape:
CVE-2021-44228). - CWE — weakness class (for example injection, broken auth) — helps group root causes.
- CVSS — score / vector that estimates severity; useful but not the only signal (context matters).
- KEV — CISA Known Exploited Vulnerabilities catalog: flaws seen abused in the wild. Treat KEV hits on your estate as emergency queue work.
- Advisory — vendor bulletin that says which builds are fixed.
Educational warning: any scanner or exploit research stays in your isolated lab or under written authorisation. No scanning neighbour networks or random public IPs.
Real incident: Equifax (2017) — unpatched known CVE
Public reporting on the Equifax 2017 breach described attackers abusing a known Apache Struts vulnerability after a patch was already available. Massive personal data exposure followed, with long regulatory and trust fallout.
Takeaways (vertical):
- What happened — known CVE; patch existed; exploitation window stayed open.
- What went wrong (theme) — inventory / patch SLA / verification culture failed under real complexity.
- Care-take — internet-facing apps need faster patch clocks than interior printers.
- Care-take — “scanner green last quarter” is not continuous assurance.
- Care-take — track KEV-class items with executive visibility.
- Bonus parallel — WannaCry (2017) showed wormable unpatched Windows estates collapsing in days.
Where does KEV fit next to CVSS?
- CVSS answers “how bad could this be in a generic model?”
- KEV answers “are defenders already seeing this abused?”
- Asset context answers “does our exposure make it urgent?”
- Use all three — never CVSS alone, never “internet blog severity” alone.
- If a KEV item does not apply to your software list, document the exclusion with inventory proof.
Red Team vs Blue Team (awareness only)
Red Team — what attackers try
- Race defenders between public CVE disclosure and your patch window.
- Focus on forgotten internet-facing apps and abandoned admin panels.
- Chain a medium CVE with weak credentials (high-level idea only).
Blue Team — defend, detect, respond
- Maintain asset inventory tied to owners.
- Prioritise KEV + exposed criticals; document exceptions with expiry dates.
- Patch pipelines with staged rings and rollback plans.
- Verify with authenticated re-scans and version evidence in tickets.
- Watch exploit-attempt noise in WAF / IDS after big CVE news (detection, not offence).
How do I run the loop step by step?
Step 1 — Build a usable inventory
- List servers, endpoints, cloud accounts, containers, and critical SaaS.
- Record owner, data class, and internet exposure.
- For a Nashik grape exporter SMB: start with Microsoft 365, one public website host, and finance laptops — not “every IoT bulb”.
Step 2 — Discover findings safely
- Prefer authenticated vulnerability scans on systems you own / are authorised to test.
- Pull OS vendor channels and language dependency alerts (npm / pip / Maven, etc.).
- Subscribe to CISA KEV updates and major vendor PSIRTs.
- Deduplicate scanner noise; mark false positives with evidence.
Step 3 — Prioritise like a defender
- Is it on KEV? Escalate.
- Is the asset internet-facing or holding personal / payment data?
- Is a reliable fix available? If not, plan a compensating control (WAF rule, disable feature, segment).
- Write an SLA: for example KEV on exposed assets in days, not months.
Step 4 — Patch or mitigate
- Stage in test → pilot → broad.
- Read vendor notes for breaking changes.
- Prefer supported upgrade paths over forever “hotfix folklore”.
- Temporary mitigations must have an expiry and owner.
Step 5 — Verify (the step students skip)
- Confirm package / build version on a sample of hosts.
- Re-scan the same authenticated policy; expect the CVE to clear.
- Attach screenshots or CLI evidence to the ticket.
- If still open: wrong asset, incomplete cluster, or scanner plugin lag — investigate, do not close blind.
Step 6 — Measure and improve
- Open aging by severity.
- Mean time to remediate for KEV.
- Recurring CVE families → root-cause (old base image, abandoned app).
- Tabletop: “KEV drops Friday evening — who patches?”
Step 7 — Communicate without fear theatre
- Tell leadership: exposed KEV count, age of oldest critical, next patch window.
- Tell engineers: exact packages and rollback owners — not only a severity colour.
- Tell auditors: evidence of verify, not only “we scanned”.
- After a mass-CVE week, publish a short internal FAQ (what we run, what we patched, what remains).
Ravindra Bagale's Tip
💡 Many students panic at CVSS 9.8, then dump an internal printer CVE and an internet Struts CVE in one bucket. First KEV + exposure + data class. Then score. If you do not verify, the ticket can be green and an Equifax-style gap remains. Remember: find ≠ fixed.
Ravindra Bagale's Tip – मराठी
💡 खूप students CVSS 9.8 पाहून panic, पण internal printer CVE आणि internet Struts CVE एकाच bucket मध्ये टाकतात. आधी KEV + exposure + data class. मग score. Verify नाही केला तर ticket green असला तरी Equifax-style gap राहते. लक्षात ठेवा: find ≠ fixed.
Ravindra Bagale's Tip – हिंदी
💡 बहुत students CVSS 9.8 देखकर panic, लेकिन internal printer CVE और internet Struts CVE एक ही bucket में डालते हैं. पहले KEV + exposure + data class. फिर score. Verify नहीं किया तो ticket green हो फिर भी Equifax-style gap रहता है. याद रखो: find ≠ fixed.
Care-take — keep the program honest
- Named owners per asset class.
- Exception register with expiry (no eternal “risk accepted”).
- Change windows and rollback tested once.
- Dependency / container base images in the same program as VMs.
- After big CVE weeks: hunt for exploit attempts in logs (blue detection).
- Never celebrate “zero findings” from an unauthenticated scan of three hosts.
How do I fix common vuln-mgmt mistakes?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| Huge PDF, nothing patched | No owners / SLA | Assign queues; start with KEV + exposed |
| Patched but scanner still red | Wrong host or no verify | Version check + authenticated re-scan |
| “Critical” ignore list forever | Exceptions without expiry | Time-box; review monthly |
| Same CVE every quarter | Golden image / AMI stale | Rebuild pipeline; patch the template |
| Dev scanned prod by surprise | No authorisation path | Written scope; change calendar |
| Only network CVE focus | Missed library CVEs | Add SCA / dependency alerts |
Try it at home
On a lab VM you own (educational):
- Note current package versions for one service (
nginx -vorhttpd -v). - Read one public CVE advisory page (no exploit steps) and write the fixed version.
- Open CISA KEV and skim five entries — practice prioritisation language.
- Write a 5-line ticket template: asset, CVE, KEV yes/no, fix plan, verify evidence.
- Do not scan anything you do not own.
Learn it properly
Course lessons:
- Vulnerability, CVE, CWE and CVSS
- Reading results — false positives and prioritising
- Writing a vulnerability report
- Red vs blue project and real incidents
Related guides: Nmap ethical basics · Linux harden checklist · IR first 24 hours · OWASP Top 10
Got it? Vuln mgmt = inventory → find → prioritise (KEV!) → patch → verify. Track CVE IDs; a scan PDF is not wallpaper. Equifax lesson: known patch ignored = disaster. Lab / authorisation only. Next: learn Windows logs + Sysmon SOC view.
समजलं का? Vuln mgmt = inventory → find → prioritise (KEV!) → patch → verify. CVE ID track करायचा; scan PDF wallpaper नाही. Equifax lesson: known patch ignored = disaster. Lab / authorisation only. आता Windows logs + Sysmon SOC view शिका.
समझ में आया? Vuln mgmt = inventory → find → prioritise (KEV!) → patch → verify. CVE ID track करना; scan PDF wallpaper नहीं. Equifax lesson: known patch ignored = disaster. Lab / authorisation only. आगे Windows logs + Sysmon SOC view सीखो.
Frequently asked questions
What is a CVE?
A Common Vulnerabilities and Exposures ID that publicly tracks a known software weakness.
What is CISA KEV?
The Known Exploited Vulnerabilities catalog — flaws observed abused in the wild; prioritise them on your estate.
Is a CVSS score enough to prioritise?
No. Combine CVSS with KEV, exposure and data sensitivity.
When is scanning allowed?
Only on systems you own or that are named in written authorisation — never random public targets.
What does verification mean?
Prove the fixed version is present and that a re-scan clears the finding, with evidence in the ticket.
Where are deeper lessons on this site?
Cyber Part 10 vulnerability scanning chapters and related hardening guides.