ALL PASS, NO FAIL!

CEH v13 Module 5: Vulnerability Analysis

Vulnerability analysis is the process of identifying, quantifying, and prioritizing vulnerabilities in systems and applications. This module covers vulnerability assessment methodologies, scanning tools like Nessus and OpenVAS, CVE/CVSS frameworks, patch management, and risk assessment strategies.

The CEHStudy app carries 5 flashcards for Module 5 in 1 section — open the Module 5 deck and drill the CVSS bands until you can classify a score in seconds.

Key Topics Covered

Important Terms & Concepts

Vulnerability Assessment: The process of identifying, quantifying, and prioritizing vulnerabilities using automated tools and manual analysis to understand an organization's security posture.
CVE (Common Vulnerabilities and Exposures): A standardized dictionary of publicly disclosed security vulnerabilities. Each CVE has a unique identifier (e.g., CVE-2024-1234).
CVSS (Common Vulnerability Scoring System): A framework for scoring vulnerability severity from 0.0 to 10.0. Scores: 0.0-3.9 (Low), 4.0-6.9 (Medium), 7.0-8.9 (High), 9.0-10.0 (Critical).
Nessus: One of the most widely used vulnerability scanning tools by Tenable. Provides comprehensive scanning for networks, web apps, databases, and cloud environments.
OpenVAS: An open-source vulnerability scanner that provides full-featured vulnerability detection and reporting capabilities.
False positive: When a scanner reports a vulnerability that does not actually exist. A major challenge in vulnerability management.
False negative: When a scanner fails to detect a vulnerability that does exist. More dangerous than false positives as it creates false confidence.

CVSS Score Categories

How to Study This Module

Frequently Asked Questions

What is vulnerability assessment?
The process of identifying, quantifying, and prioritizing vulnerabilities using automated tools to proactively discover security weaknesses before attackers can exploit them.

How does vulnerability assessment differ from penetration testing?
Vulnerability assessment identifies and lists vulnerabilities. Penetration testing actively exploits them to demonstrate the actual impact. VA is broader; PT is deeper.

Related Modules

What is Vulnerability Analysis in Ethical Hacking?

Vulnerability Analysis is a core domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. Unlike scanning (which finds open ports) or enumeration (which extracts data), it matches discovered services and configurations against known vulnerability databases to identify specific CVEs that could be weaponized, with CVSS scoring ranking findings by severity for remediation priority. Module 5 accounts for approximately 10% of CEH v13 exam questions.

Key Concepts in Vulnerability Analysis

Common Exam Mistakes in Module 5

Misplacing the CVSS band boundaries: 0.0–3.9 Low, 4.0–6.9 Medium, 7.0–8.9 High, 9.0–10.0 Critical — a 7.0 score is High, not Medium, and 9.0 opens the Critical band.
Reporting scanner output without verification: False positives come from misconfigured scanners and wrong version detection, so confirm every finding manually before it enters a remediation report. The opposite trap — a false negative the scanner missed — creates false confidence.
Mixing up who maintains what: CVE identifiers are assigned by MITRE, not OWASP or NIST. Distractors also swap tool roles: Burp Suite and Acunetix are web-focused, Qualys is the cloud platform, Nexpose (Rapid7) prioritizes by risk, OpenVAS is Nessus's open-source alternative.

Tools Used in Vulnerability Analysis

The scanners the CEH exam sorts into network-based, host-based and web-focused categories:

Worked Example: Prioritizing Two Findings from One Scan

An authenticated Nessus scan of an authorized environment returns two findings: Finding A scores 9.8 (Critical) on an air-gapped test host with no public exploit code; Finding B scores 7.2 (High) on an internet-facing web server with a circulating proof-of-concept.

Ranking logic: patch Finding B first. CVSS measures inherent severity; remediation priority adds exposure, available exploits and compensating controls — so the internet-facing host outranks the segmented test box despite its lower score. Verify both findings to rule out false positives, then schedule Finding A against the normal high-severity SLA.

How to Study Vulnerability Analysis for the CEH v13 Exam

To study Module 5:

  1. Memorize CVSS score ranges: 0.0–3.9 Low, 4.0–6.9 Medium, 7.0–8.9 High, 9.0–10.0 Critical — and each CVSS metric (AV, AC, PR, UI, S, C, I, A)
  2. Distinguish vulnerability assessment (identifying), penetration testing (exploiting) and security auditing (compliance)
  3. Hands-on: download Nessus Essentials (free), scan a Metasploitable 2 VM, find at least 5 vulnerabilities, look up their CVE IDs, verify their CVSS scores, and write a one-paragraph remediation recommendation for each
  4. Review Module 4 (Enumeration) — service identification feeds scanning — and Module 6 (System Hacking) — identified vulnerabilities get exploited

Frequently Asked Questions About Vulnerability Analysis

What is the difference between vulnerability assessment and penetration testing?

Vulnerability assessment is broad and automated: it identifies and lists security weaknesses across an environment without exploiting them. Penetration testing goes further, actively exploiting findings to demonstrate real-world impact. On the CEH exam, VA answers "what are the gaps?" while PT answers "how badly can they be exploited?" Both require written authorization; PT typically needs a more detailed scope and rules of engagement.

How does CVSS scoring work on the CEH exam?

CVSS v3.1 assigns a base score (0.0–10.0) calculated from eight metrics: Attack Vector (Network/Adjacent/Local/Physical), Attack Complexity (Low/High), Privileges Required (None/Low/High), User Interaction (None/Required), Scope (Unchanged/Changed), and impact on Confidentiality, Integrity, and Availability (None/Low/High). Exam questions give a vulnerability description and ask for the correct score or severity category. Tip: no user interaction, no privileges, network-exploitable with high impact on all three CIA dimensions scores 9.0 or above (Critical).

Related CEH v13 Modules

Related Glossary Terms