Vulnerability tree
From Cramsession
✍️ Verified Author: Mflavell • Click to view professional profile & credentials
Cybersecurity > Vulnerability tree
This tree is used to link vulnerabilities to remediation actions.
Tree Design
1 [CVE] [CVE] [CVE] [CVE]
\ / \ /
2 [Module] [Module]
\ /
3 [Product]
|
4 [Action]
Implications
- Exploits at layer 1, result from..
- vulnerabilities in layer 2 due to...
- Modules that is implemented in the product or solution at layer 3...
- That the action at layer 4 can resolve by updating or removing the product.