> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/vulnerability-assessment.md).

# Vulnerability Assessment

Cortex XDR vulnerability assessment enables you to identify and quantify the security vulnerabilities on an endpoint. After evaluating the risks to which each endpoint is exposed and the vulnerability status of an installed application in your network, you can mitigate and patch these vulnerabilities on all the endpoints in your organization.

<details>

<summary>Legacy Vulnerability Assessment</summary>

For a comprehensive understanding of the vulnerability severity, Cortex XDR retrieves the latest data for each Common Vulnerabilities and Exposures (CVE) from the [NIST National Vulnerability Database](https://nvd.nist.gov/), including CVE severity and metrics.

{% hint style="warning" %}

### Danger

The following are prerequisites for Cortex XDR to perform a vulnerability assessment of your endpoints.
{% endhint %}

| Requirement           | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| --------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Licenses and Add-ons  | <ul><li>Cortex XDR Pro per Endpoint license.</li><li>Host Insights Add-on.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Supported Platforms   | <ul><li><p><strong>Windows</strong></p><ul><li>Cortex XDR agent 7.1 or a later release.</li><li>Cortex XDR lists only CVEs relating to the operating system, and not CVEs relating to applications provided by other vendors.</li><li>Cortex XDR retrieves the latest data for each CVE from the NIST National Vulnerability Database as well as from the Microsoft Security Response Center (MSRC).</li><li>Cortex XDR collects KB and application information from the agents but calculates CVE only for KBs based on the data collected from MSRC and other sources</li><li>For endpoints running Windows Insider, Cortex XDR cannot guarantee an accurate CVE assessment.</li><li>Cortex XDR does not display open CVEs for endpoints running Windows releases for which Microsoft no longer fixes CVEs.</li></ul></li><li><p><strong>Linux</strong></p><ul><li>Cortex XDR agent 7.1 or a later release.</li></ul><p>Cortex XDR collects all the information about the operating system and the installed applications, and calculates CVE based on the the latest data retrieved from the NIST.</p></li><li><p><strong>MacOS</strong></p><ul><li>Cortex XDR agent 7.1 or a later release.</li><li>Cortex XDR collects only the applications list from MacOS without CVE calculation.</li></ul></li></ul><p>If Cortex XDR doesn't match any CVE to its corresponding application, an error message is displayed, "No CVEs Found".</p> |
| Setup and Permissions | Ensure [Host Inventory Data Collection](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-agent-settings-profiles.md) is enabled for your Cortex XDR agent.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Limitations           | Cortex XDR calculates CVEs for applications according to the application version, and not according to application build numbers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |

</details>

<details>

<summary>Enhanced Vulnerability Assessment</summary>

The **Enhanced Vulnerability Assessment** mode uses an advanced algorithm to collect extensive details on CVEs from comprehensive databases and to produce an in-depth analysis of the endpoint vulnerabilities. Turn on the **Enhanced Vulnerability Assessment** mode from **Settings** → **Configurations** → **Vulnerability Assessment**. This option may be disabled for the first few days after updating Cortex XDR as the **Enhanced Vulnerability Assessment** engine is initialized.

{% hint style="warning" %}

### Danger

The following are prerequisites for Cortex XDR to perform an **Enhanced Vulnerability Assessment** of your endpoints.
{% endhint %}

| Requirement                        | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ---------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Licenses and Add-ons               | <ul><li>Cortex XDR Pro per Endpoint license.</li><li>Host Insights Add-on.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Supported Platforms                | <ul><li><p><strong>Windows</strong></p><ul><li>Cortex XDR agent 8.3 or a later release.</li><li>Cortex XDR collects all the information about the operating system and the installed applications, and calculates CVE based on the latest data retrieved from the NIST.</li><li>CVEs that apply to applications that are installed by one user aren't detected when another user without the application installed is logged in during the scan.</li></ul></li><li><p><strong>MacOS</strong></p><ul><li>Cortex XDR agent 8.3 or a later release.</li><li>Cortex XDR collects all the information about the operating system and the installed applications, and calculates CVE based on the latest data retrieved from the NIST.</li></ul></li></ul> |
| Setup and Permissions              | Ensure [Host Inventory Data Collection](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-agent-settings-profiles.md) is enabled for your Cortex XDR agent.                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Certificates for Windows and macOS | <p>When Advanced Vulnerability and Assessment is enabled, these certificates are a prerequisite for Windows and macOS.</p><p>Download the certificates from <a href="#certificates-for-windows-and-macos">here</a>.</p><ul><li>Import the <em>Digicert Trusted Root G4</em> certificate into the Trusted Root Certification Authorities store in the local machine.</li><li><p>In some environments, if the scan does not initialize, the <em>DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1</em> certificate, may also be required.</p><p>Import the signed certificate into the Intermediate Certification Authorities store in the local machine.</p></li></ul>                                                                         |
| Limitations                        | <ul><li>Some CVEs may be outdated if the Cortex XDR agent wasn't updated recently.</li><li>Application versions which have reached end-of-life (EOL) may have their version listed as 0. This doesn't affect the detection of the CVEs.</li><li>Some applications are listed twice. One of the instances may display <code>invalid version</code>, however, this doesn't affect the functionality.</li><li>The scanning process may impact performance on the Cortex XDR agent during scanning. The scan may take up to two minutes.</li></ul>                                                                                                                                                                                                       |

#### Certificates for Windows and macOS

{% file src="/files/4Y7uQzA4nEsmT66cZrKe" %}

</details>

You can access the **Vulnerability Assessment** panel from **Assets** → **Vulnerability Assessment**.

Once enabling the feature for the first time, it may take up to a week to get the updated data into the platform. Re-collecting the data from all endpoints in your network could take up to 6 hours. After that, Cortex XDR initiates periodical recalculations to rescan the endpoints and retrieve the updated data. If at any point you want to force data recalculation, click **Recalculate**. The recalculation performed by any user on a tenant updates the list displayed to every user on the same tenant.

<details>

<summary>CVE Analysis</summary>

To evaluate the extent and severity of each CVE across your endpoints, you can drill down into each CVE in Cortex XDR and view all the endpoints and applications in your environment that are impacted by the CVE. Cortex XDR retrieves the latest information from the NIST public database. From Assets → Host Insights → **Vulnerability Assessment**, select **CVEs** on the upper-right bar. This information is also available in the va\_cves dataset, which you can use to build queries in XQL Search.

If you have the Identity Threat Module enabled, you can also view the CVE analysis in the Host Risk View. To do so, from **Assets** → **Asset Scores**, select the **Hosts** tab, right click on any endpoint, and select **Open Host Risk View**.

For each vulnerability, Cortex XDR displays the following default and optional values.

| Value                  | Description                                                                                                                                                                                                                                                     |
| ---------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Affected endpoints** | The number of endpoints that are currently affected by this CVE. For excluded CVEs, the affected endpoints are **N/A**.                                                                                                                                         |
| **Applications**       | The names of the applications affected by this CVE.                                                                                                                                                                                                             |
| **CVE**                | <p>The name of the CVE.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Tip</strong></p><p>You can click each individual CVE to view in-depth details about it on a panel that appears on the right.</p></div> |
| **Description**        | The general NIST description of the CVE.                                                                                                                                                                                                                        |
| **Excluded**           | Indicates whether this CVE is excluded from all endpoint and application views and filters, and from all Host Insights widgets.                                                                                                                                 |
| **Platforms**          | The name and version of the operating system affected by this CVE.                                                                                                                                                                                              |
| **Severity**           | The severity level (Critical, High, Medium, or Low) of the CVE as ranked in the NIST database.                                                                                                                                                                  |
| **Severity score**     | The CVE severity score is based on the NIST Common Vulnerability Scoring System (CVSS). Click the score to see the full CVSS description.                                                                                                                       |

You can perform the following actions from Cortex XDR as you analyze the existing vulnerabilities:

* **View CVE details**—Left-click the CVE to view in-depth details about it on a panel that appears on the right. Use the in-panel links as needed.
* **View a complete list of all endpoints in your network that are impacted by a CVE**—Right-click the CVE and then select **View affected endpoints**.
* **Learn more about the applications in your network that are impacted by a CVE**—Right-click the CVE and then select **View applications**.
* **Exclude irrelevant CVEs from your endpoints and applications analysis**—Right-click the CVE and then select **Exclude**. You can add a comment if needed, as well as **Report CVE as incorrect** for further analysis and investigation by Palo Alto Networks. The CVE is grayed out and labeled **Excluded** and no longer appears on the **Endpoints** and **Applications** views in **Vulnerability Assessment**, or in the Host Insights widgets. To restore the CVE, you can right-click the CVE and **Undo exclusion** at any time.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>The CVE will be removed/reinstated to all views, filters, and widgets after the next vulnerability recalculation.</p></div>

</details>

<details>

<summary>Endpoint Analysis</summary>

To help you assess the vulnerability status of an endpoint, Cortex XDR provides a full list of all installed applications and existing CVEs per endpoint and also assigns each endpoint a vulnerability severity score that reflects the highest NIST vulnerability score detected on the endpoint. This information helps you to determine the best course of action for remediating each endpoint. From Assets → **Vulnerability Assessment**, select **Endpoints** on the upper-right bar. This information is also available in the va\_endpoints dataset. In addition, the host\_inventory\_endpoints preset lists all endpoints, CVE data, and additional metadata regarding the endpoint information. You can use this dataset and preset to build queries in XQL Search.

For each vulnerability, Cortex XDR displays the following default and optional values.

| Value                       | Description                                                                                                                                                                                                                                                               |
| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **CVEs**                    | A list of all CVEs that exist on applications that are installed on the endpoint.                                                                                                                                                                                         |
| **Endpoint ID**             | Unique ID assigned by Cortex XDR that identifies the endpoint.                                                                                                                                                                                                            |
| **Endpoint name**           | <p>Hostname of the endpoint.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Tip</strong></p><p>You can click each individual endpoint to view in-depth details about it on a panel that appears on the right.</p></div> |
| **Last Reported Timestamp** | The date and time of the last time the Cortex XDR agent started the process of reporting its application inventory to Cortex XDR.                                                                                                                                         |
| **MAC address**             | The MAC address associated with the endpoint.                                                                                                                                                                                                                             |
| **IP address**              | The IP address associated with the endpoint.                                                                                                                                                                                                                              |
| **Platform**                | The name of the platform running on the endpoint.                                                                                                                                                                                                                         |
| **Severity**                | The severity level (Critical, High, Medium, or Low) of the CVE as ranked in the NIST database.                                                                                                                                                                            |
| **Severity score**          | The CVE severity score based on the NIST Common Vulnerability Scoring System (CVSS). Click the score to see the full CVSS description.                                                                                                                                    |

You can perform the following actions from Cortex XDR as you investigate and remediate your endpoints:

* **View endpoint details**—Left-click the endpoint to view in-depth details about it on a panel that appears on the right. Use the in-panel links as needed.
* **View a complete list of all applications installed on an endpoint**—Right-click the endpoint and then select **View installed applications**. This list includes the application name, and version, of applications on the endpoint. If an installed application has known vulnerabilities, Cortex XDR also displays the list of CVEs and the highest **Severity**.
* (Windows only) **Isolate an endpoint from your network**—Right-click the endpoint and then select **Isolate the endpoint** before or during your remediation to allow the Cortex XDR agent to communicate only with Cortex XDR .
* (Windows only) **View a complete list of all KBs installed on an endpoint**—Right-click the endpoint and then select **View installed KBs**. This list includes all the Microsoft Windows patches that were installed on the endpoint and a link to the Microsoft official Knowledge Base (KB) support article. This information is also available in the host\_inventory\_kbs preset, which you can use to build queries in XQL Search.
* **Retrieve an updated list of applications installed on an endpoint**—Right-click the endpoint and then select **Rescan endpoint**.

</details>

<details>

<summary>Application Analysis</summary>

You can assess the vulnerability status of applications in your network using the Host inventory. Cortex XDR compiles an application inventory of all the applications installed in your network by collecting from each Cortex XDR agent the list of installed applications. For each application on the list, you can see the existing CVEs and the vulnerability severity score that reflects the highest NIST vulnerability score detected for the application. Any new application installed on the endpoint will appear in Cortex XDR within 24 hours. Alternatively, you can re-scan the endpoint to retrieve the most updated list.

{% hint style="info" %}

### Note

Starting with macOS 10.15, Mac built-in system applications are not reported by the Cortex XDR agent and are not part of the Cortex XDR Application Inventory.
{% endhint %}

From **Incident Response** → **Host Inventory**, select **Applications**.

* To view the details of all the endpoints in your network on which an application is installed, right-click the application and select **View endpoints**.
* To view in-depth details about the application, left-click the application name.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/vulnerability-assessment.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
