OT IDS

Vulnerabilities & Risk

Vulnerability exposure across the deployed estate — severity, exploitability, aging and reporting performance, with the priority logic applied to every finding.

Total vulnerabilities
22.4K
across 82 deployed sites
Critical severity
1,708
7.6% of total
CVSS 10 vulnerabilities
51
maximum severity score
Highly exploitable
355
EPSS above 50%
Reported
16.9K
75.6% of total
Unreported
5,453
awaiting customer report
Breaching SLA
309
critical vulns past remediation SLA

Severity breakdown

22.4K open vulnerabilities by severity
Critical · 1,708 (7.6%)High · 4,668 (20.8%)Medium · 9,059 (40.5%)Low · 6,954 (31.1%)

Priority logic

how findings are ranked
P1CVSS 10 + EPSS > 50% + critical asset
P2Critical/High CVSS + high asset criticality
P3Medium severity or lower exploitability
P4Low severity or informational
Priority = CVSS + EPSS + asset criticality + exposure + business impact

Vulnerability aging

open vulnerabilities by time since detection
20.0% of open vulnerabilities are older than 90 days.

Exploitability view

top 10 CVEs by EPSS score across affected sites

Top vulnerable sites

open vulnerabilities per site, top 8

Top vulnerabilities

catalog CVEs present in the filtered estate
CVEVulnerabilityVendorCVSSEPSS %Affected assetsSitesPriority
CVE-2021-44228Apache Log4j RCE on OT management serversMultiple10.097.4%40625P1
CVE-2019-0708RDP "BlueKeep" RCE on HMI/EWS hostsMicrosoft9.896.9%26217P1
CVE-2017-0144SMBv1 "EternalBlue" on legacy Windows nodesMicrosoft9.394.2%28522P2
CVE-2015-5374Siemens SIPROTEC denial of serviceSiemens7.871.3%51430P2
CVE-2022-1161Rockwell Logix controller code modificationRockwell10.061.2%43328P1
CVE-2023-3595Rockwell 1756 EN2/EN3 unauthenticated RCERockwell9.855.8%39324P1
CVE-2021-22681Rockwell Studio 5000 key extractionRockwell10.042.7%44524P2
CVE-2022-45788Schneider Modicon remote code executionSchneider9.831.5%49131P2
CVE-2021-33723Siemens SINEC NMS privilege escalationSiemens8.817.6%51630P3
CVE-2020-12030Emerson WirelessHART gateway auth bypassEmerson9.112.4%26320P2
CVE-2020-14509GE Reason RT430 hardcoded credentialsGE9.89.8%43531P2
CVE-2022-38465Siemens S7-1500 global key exposureSiemens9.38.9%43432P2
CVE-2020-25176Mitsubishi MELSEC iQ-R DoSMitsubishi7.56.2%54535P3
CVE-2016-2183SWEET32 3DES on OT web interfacesMultiple5.35.7%47228P3
CVE-2019-6857Schneider Modicon M580 DoSSchneider7.54.1%39226P3
CVE-2017-14463Allen-Bradley MicroLogix fault DoSRockwell7.53.9%33420P3
CVE-2020-7491Schneider Triconex legacy debug portSchneider7.43.3%29022P3
CVE-2019-10936Siemens PROFINET DoSSiemens6.52.8%38225P3
CVE-2018-4850Siemens S7-400 crafted packet DoSSiemens6.52.1%38325P3
CVE-2019-13945Siemens S7-1200 hardware access modeSiemens4.61.2%23320P4
All times shown in local time of selected region · Data refresh every 15 minutes