CVE Intelligence
CVE Intelligence
Section titled “CVE Intelligence”NEURO integrates with the National Vulnerability Database (NVD) and MITRE to provide real-time CVE intelligence. Automatically enrich your findings with official vulnerability data.
Overview
Section titled “Overview”CVE Intelligence provides:
- Automatic CVE ID detection
- Real-time NVD data lookup
- Official CVSS scores
- Authoritative descriptions
- CWE mappings
- Reference links
How It Works
Section titled “How It Works”Using CVE Lookup
Section titled “Using CVE Lookup”Automatic Detection
Section titled “Automatic Detection”NEURO automatically detects CVE IDs in:
- Finding title
- Description text
When detected:
- CVE ID is extracted
- NVD is queried
- Data is populated
- References are added
Manual CVE Entry
Section titled “Manual CVE Entry”- In the finding form, locate CVE ID field
- Enter the CVE ID:
CVE-2024-12345 - Click Lookup or Tab out
- Data populates automatically
What’s Retrieved
Section titled “What’s Retrieved”| Field | Source | Description |
|---|---|---|
| CVSS Score | NVD | Official base score |
| CVSS Vector | NVD | Full vector string |
| Severity | Calculated | Based on CVSS score |
| CWE ID | NVD | Weakness classification |
| Description | NVD | Official vulnerability description |
| References | NVD | Official advisories and links |
Data Sources
Section titled “Data Sources”National Vulnerability Database (NVD)
Section titled “National Vulnerability Database (NVD)”Primary source for:
- CVSS 3.1 scores
- Official descriptions
- CWE mappings
- Reference URLs
- Affected products (CPE)
MITRE CVE
Section titled “MITRE CVE”Fallback source for:
- CVE descriptions
- Basic information
- When NVD data unavailable
CISA KEV
Section titled “CISA KEV”For Known Exploited Vulnerabilities:
- Exploitation status indicator
- Due date information
- Remediation guidance
CVE in Findings
Section titled “CVE in Findings”Creating CVE-Based Findings
Section titled “Creating CVE-Based Findings”- Click + New Finding
- Title:
CVE-2024-12345orCVE-2024-12345 - Vulnerability Name - Click Generate with AI
- Result:
- Official CVE data from NVD
- AI-generated remediation
- Combined references
CVE Without AI
Section titled “CVE Without AI”To get just CVE data:
- Create finding with any title
- Enter CVE ID in the CVE field
- Click lookup icon
- Official data populates
- Write description manually
Multiple CVEs
Section titled “Multiple CVEs”For findings affecting multiple CVEs:
- Enter primary CVE in the CVE field
- Add additional CVEs in references
- Document relationship in description
CVSS Handling
Section titled “CVSS Handling”Score Priority
Section titled “Score Priority”When CVE is looked up:
- Official NVD CVSS score is used
- Overwrites AI-suggested score
- Vector string is populated
Adjusting CVSS
Section titled “Adjusting CVSS”You may adjust CVSS when:
- Environmental factors apply
- Temporal metrics relevant
- Specific context differs
Original CVE score is preserved in references.
CWE Mapping
Section titled “CWE Mapping”CVE lookups include CWE (Common Weakness Enumeration):
| CWE ID | Category |
|---|---|
| CWE-79 | Cross-site Scripting |
| CWE-89 | SQL Injection |
| CWE-287 | Improper Authentication |
| CWE-200 | Information Exposure |
CWE helps:
- Categorize findings
- Filter by weakness type
- Map to compliance controls
CISA KEV Integration
Section titled “CISA KEV Integration”For actively exploited vulnerabilities:
KEV Indicator
Section titled “KEV Indicator”When a CVE is in CISA’s KEV:
- “Known Exploited” badge appears
- Increased urgency highlighted
- Due date shown (if applicable)
KEV Benefits
Section titled “KEV Benefits”- Identify highest priority CVEs
- Track exploitation status
- Meet federal requirements
- Prioritize remediation
Reference Management
Section titled “Reference Management”Automatic References
Section titled “Automatic References”CVE lookup adds references:
- NVD page
- Vendor advisories
- Security bulletins
- Exploit databases
Reference Types
Section titled “Reference Types”| Type | Example |
|---|---|
| NVD | nvd.nist.gov link |
| Vendor | Microsoft/Cisco advisory |
| Advisory | Security bulletin |
| Exploit | Exploit-DB reference |
| Patch | Update/fix links |
Search by CVE
Section titled “Search by CVE”Find existing findings by CVE:
- Go to Findings
- Use search:
CVE-2024-12345 - View all related findings
Bulk CVE Import
Section titled “Bulk CVE Import”Import multiple CVE-based findings:
- Prepare CVE list
- Go to Findings → Import
- Select CVE Import
- Paste CVE IDs (one per line)
- Click Import
- Findings created with CVE data
Troubleshooting
Section titled “Troubleshooting”CVE Not Found
Section titled “CVE Not Found”If CVE lookup fails:
- Verify CVE ID format (CVE-YYYY-NNNNN)
- Check CVE exists (recently assigned CVEs may not be in NVD)
- Try again later (API may be unavailable)
Missing Data
Section titled “Missing Data”Some CVEs have incomplete NVD data:
- Reserved but not published
- Recently assigned
- Analysis pending
Conflicting Scores
Section titled “Conflicting Scores”If your assessment differs from NVD:
- Document reasoning in finding
- Keep original CVE score as reference
- Note adjusted score and justification
Best Practices
Section titled “Best Practices”CVE Usage
Section titled “CVE Usage”- Always link CVEs when applicable
- Verify CVE accuracy - ensure it matches your finding
- Add context - CVE is the vulnerability, your finding is the instance
- Update periodically - CVE data can change
Documentation
Section titled “Documentation”Include in your finding:
- CVE ID
- Your specific evidence
- Environment context
- Adjusted recommendations
Next: Learn about the AI Chat Assistant