Cisco Cisco Firepower Management Center 4000 Entwickleranleitung

Seite von 180
 
6-57
FireSIGHT System Database Access Guide
 
Chapter 6      Schema: Discovery Event and Network Map Tables
  rna_vuln
rna_vuln Joins
The following table describes the joins you can perform on the 
rna_vuln
 table.
impact
The vulnerability impact, corresponding to the impact level determined through 
correlation of intrusion data, discovery events, and vulnerability assessments. The value 
can be from 
1
 to 
10
, with 
10
 being the most severe. The impact value of a vulnerability is 
determined by the writer of the Bugtraq entry.
local
Indicates whether the vulnerability must be exploited locally:
  •
TRUE
  •
FALSE
long_description
A general description of the vulnerability.
mitigation
A description of how you can mitigate the vulnerability.
modified_date
The date of the most recent modification to the vulnerability, if applicable.
publish_date
The date the vulnerability was published.
remote
Indicates whether the vulnerability can be exploited across a network:
  •
TRUE
  •
FALSE
rna_vuln_id
The Cisco vulnerability ID number that the system uses to track vulnerabilities.
scenario
A description of a scenario where an attacker is exploiting the vulnerability.
short_description
A summary description of the vulnerability.
snort_id
The identification number associated with the vulnerability in the Snort ID (SID) database. 
That is, if an intrusion rule can detect network traffic that exploits a particular 
vulnerability, that vulnerability is associated with the intrusion rule’s SID.
solution
The solution to the vulnerability.
technical_description
The technical description of the vulnerability.
title
The title of the vulnerability.
Table 6-51
rna_vuln Fields (continued)
Field
Description
Table 6-52
rna_vuln Joins 
You can join this table on...
And...
rna_vuln_id
or
bugtraq_id