Exposures
The new Exposures view provides a CVE-centric inventory of vulnerabilities identified across connected sources. Exposures include key prioritisation context such as Vulnerability Risk Rating, impacted assets, last discovered date, exploit information, tags, and source attribution.
By combining vulnerability intelligence with exposure and asset context, Remediation Insights helps security teams focus on the vulnerabilities that present the highest risk to the organisation rather than relying on CVSS alone.
The following details are captured and displayed in Remediation Insights > Exposures.
- Exposure (CVE): This column lists the CVE identifier for each detected vulnerability. Select a CVE to open the detailed exposure profile, where you can review vulnerability information, associated threats, available fixes, and impacted assets. Use this column to identify, track, and investigate specific vulnerabilities across your environment.
-
Vulnerability Risk Rating: The VRR score indicates the risk level of the exposure. Higher scores represent higher risk and help you prioritize vulnerabilities for remediation. For more information, see What is Vulnerability Risk Rating.
-
Impacted assets: Displays all exposures or set a custom range based on the number of affected assets.
-
Predictive Compliance: Indicates remediation readiness based on discovery, agent, and patch policy coverage. For more information, see Predictive Compliance.
-
Last discovered: Displays when the system last detected the exposure to help you prioritize recent vulnerabilities. Filter the list by predefined time ranges (3, 14, 30, or 365 days) or a custom date range.
-
Source(s): Displays exposures by source, such as Ivanti, Microsoft Defender for Endpoint, or Qualys.
-
Exploits: Displays the list of exposures by exploit type, such as DoS, Privilege escalation, Remote Code Execution (RCE), Web apps, or those with no known exploits.
-
Tags: Displays the exposures with specific tags, such as operating systems, platforms, or your organization’s custom labels. You can apply multiple filters at the same time. To clear a specific filter, deselect the filter in the drop down or select No filter applied to clear all filters.
Filter the Exposures List
You can quickly narrow and prioritize exposures by applying filters to the columns in the Exposures list. Filters help you customize your view and focus on the most relevant data.
To apply a filter:
-
Select the Filter icon next to the column you want to filter.
-
Choose your filter options from the available selections or specify a custom range.
-
Select OK to apply the filter.
The filter options include:
VRR (Vulnerability Risk Rating):
-
Filter by risk levels: None, Low, Medium, High, or Critical.
-
You can also set a custom range to display specific VRR scores.
Exposure Actions
You can perform the following bulk actions on Exposures:
-
Use the Export button to export the exposures list to text (.csv). Any column filters you have applied will also apply to the export.
-
Use the Add / remove tags action menu to add new tags or remove existing tags attached to the selected exposures. Select one or more exposures (up to the supported limit - 100 exposures), and then select Add / remove tags from the Actions menu. You can add the selected exposures to the existing user defined tags or create a tag by typing a new tag name and pressing Enter. You can add multiple tags to the exposures. Once you have selected or entered the tags, click Apply tags. The tags are linked to the exposures and are visible in the Exposures page. In the exposure details page, you can view user-defined tags and system-defined tags separately.
-
Remediation-oriented actions directly from exposure workflows:
Remediation Insights now enables you to take remediation-oriented actions directly from exposure workflows. You can add selected exposures to a patch group, helping bridge the gap between vulnerability prioritisation and patch execution. This reduces manual hand-offs between security and IT teams and helps convert prioritised exposure data into actionable patching workflows inside Ivanti Neurons.
-
Use Add to patch group action in the Actions menu to add the selected exposures to the patch group.
-
Use Create new patch group action to create a new patch group. To add the selected exposures to a new patch group, In the Actions menu click Add a Patch Group, then provide a descriptive name for the group and click Add. The name must be unique and is case insensitive.
-
Ensure that you have Create New patch Groups and Modify Existing Patch Groups permissions. (Ivanti Neurons > Admin > Access Control > Roles > Permissions > Patch Management > Patch Settings > General)
Vulnerability Risk Rating
Vulnerability Risk Rating (VRR) considers industry-standard Common Vulnerability Scoring System (CVSS), Common Weakness Enumeration (CWE) data, OWASP (Open Web Application Security Project), open-source threat intelligence, subject matter expertise, trending information, and more. VRR represents the risk posed by a given vulnerability, provided as a numerical score between 0 and 10, to an organization or business. The higher the risk, the higher the VRR.
Use of Vulnerability Risk Ratings (VRR) in Vulnerability Management
To streamline and prioritize remediation efforts across our environment, we leverage Vulnerability Risk Ratings (VRR) as provided by the Ivanti platform. VRR is a numeric value ranging from 0.0 (lowest risk) to 10.0 (highest risk), reflecting the potential impact and exploitability of each vulnerability identified. The VRR is a dynamic rating based on various risk factors, including threat intelligence and vulnerability characteristics.
Within the platform, VRR values are prominently displayed in dashboards, asset inventories, and vulnerability reports. These ratings allow staff to efficiently sort and filter vulnerabilities, focusing attention and resources on the exposures that pose the highest risk to our assets and operations.
By incorporating VRR into our vulnerability management workflow, we ensure that critical issues are addressed promptly and risk is effectively reduced.
Predictive Compliance
Predictive Compliance is a leading indicator of remediation readiness for each exposure. The score helps teams understand whether impacted assets meet the required conditions for successful remediation, including Ivanti Neurons discovery detection, active Ivanti agent coverage, and an agent policy capability with an active patch configuration.
This helps security and IT teams identify remediation blockers earlier, such as assets that are not managed, do not have an active agent, or are not covered by patch capability. Teams can use this information to improve patch readiness before remediation deadlines are missed.
Compliance Criteria
For an impacted asset to be counted as compliant toward a CVE's score, it must satisfy all of the following criteria:
-
Discovered: The asset is discovered by Ivanti Neurons (via either active or passive discovery).
-
Active Agent: The asset has an Ivanti agent installed and is active.
-
Patch Policy: The asset's assigned Neurons Policy includes an active Patch configuration.
If an asset is missing data for any of the criteria listed above, it is automatically treated as non-compliant.
How the Score is Calculated
The Predictive Compliance Score is displayed as a percentage in the Predictive Compliance column for each CVE. The score represents the ratio of compliant impacted assets to the total number of impacted assets for that specific CVE.
Example:
Consider a vulnerability that impacts 10 assets in your environment:
-
Each asset accounts for an equal weight of 10% toward the overall score.
-
If only 1 asset meets all three compliance criteria (discovered, active agent, and assigned a patch policy), the Predictive Compliance Score for that CVE will display as 10%.