Affected Product Categorization helps you allocate resources and prioritize risk mitigation efforts by organizing vulnerabilities according to their root causes and affected products.
This categorization uses three fields that make it easier to analyze and address vulnerabilities across your network:
Category: Indicates the root cause type, which can be Software, OS or Hardware.
Affected product: Lists the products affected by the vulnerability.
Vendor: Identifies the vendors affected by the vulnerability.
The Category and Affected product fields are displayed by default as columns in the All vulnerabilities view. The Vendor field can be added as an optional column.
You can use these fields to filter, group, and sort vulnerabilities.
Use case: Find all CVEs affecting Microsoft Edge
Let’s explore a practical example of how you might use Affected Product Categorization to prioritize risk actions and allocate resources efficiently.
For this example, imagine you want to start addressing vulnerabilities that affect Microsoft Edge.
In your Lansweeper Site, go to Risk insights > Active vulnerabilities.
Select Filters.
Select Add filter.
From the dropdowns, select Affected product - Contains - Edge.
Select Apply.
Select Unsaved view > Save as new…
Enter a name for the view, for example, Microsoft Edge.
Optionally, add a description.
Select Save as new.
A list of relevant CVEs and their information is displayed. From here, you can refine your analysis even further. For example:
After prioritizing your list, you can learn more about each CVE and its affected assets:
Go to the CVE’s vulnerability page.
If patch information is available, scroll to the Patch information section and follow the link.
Select Affected assets to view the specific assets impacted by the vulnerability.
From there, you can begin planning and implementing remediation actions to resolve the vulnerabilities.