Vulnerability analysis is the process of identifying, quantifying, and prioritizing vulnerabilities in systems and applications. This module covers vulnerability assessment methodologies, scanning tools like Nessus and OpenVAS, CVE/CVSS frameworks, patch management, and risk assessment strategies.
The CEHStudy app carries 5 flashcards for Module 5 in 1 section — open the Module 5 deck and drill the CVSS bands until you can classify a score in seconds.
Key Topics Covered
Vulnerability assessment vs. penetration testing vs. security audit
CVE (Common Vulnerabilities and Exposures) database
Network-based vs. host-based vulnerability scanners
Patch management and remediation strategies
Risk assessment and prioritization frameworks
Compliance scanning and regulatory requirements
Important Terms & Concepts
Vulnerability Assessment: The process of identifying, quantifying, and prioritizing vulnerabilities using automated tools and manual analysis to understand an organization's security posture.
CVE (Common Vulnerabilities and Exposures): A standardized dictionary of publicly disclosed security vulnerabilities. Each CVE has a unique identifier (e.g., CVE-2024-1234).
CVSS (Common Vulnerability Scoring System): A framework for scoring vulnerability severity from 0.0 to 10.0. Scores: 0.0-3.9 (Low), 4.0-6.9 (Medium), 7.0-8.9 (High), 9.0-10.0 (Critical).
Nessus: One of the most widely used vulnerability scanning tools by Tenable. Provides comprehensive scanning for networks, web apps, databases, and cloud environments.
OpenVAS: An open-source vulnerability scanner that provides full-featured vulnerability detection and reporting capabilities.
False positive: When a scanner reports a vulnerability that does not actually exist. A major challenge in vulnerability management.
False negative: When a scanner fails to detect a vulnerability that does exist. More dangerous than false positives as it creates false confidence.
CVSS Score Categories
0.0 – 3.9 — Low severity (green)
4.0 – 6.9 — Medium severity (yellow/orange)
7.0 – 8.9 — High severity (red)
9.0 – 10.0 — Critical severity (dark red)
How to Study This Module
Understand the difference between vulnerability assessment, penetration testing, and security audits
Memorize CVSS score ranges and their severity classifications
Know the major scanning tools (Nessus, OpenVAS, Nexpose) and their key features
Understand false positive vs false negative implications in vulnerability management
Frequently Asked Questions
What is vulnerability assessment? The process of identifying, quantifying, and prioritizing vulnerabilities using automated tools to proactively discover security weaknesses before attackers can exploit them.
How does vulnerability assessment differ from penetration testing? Vulnerability assessment identifies and lists vulnerabilities. Penetration testing actively exploits them to demonstrate the actual impact. VA is broader; PT is deeper.
What is Vulnerability Analysis in Ethical Hacking?
Vulnerability Analysis is a core domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. Unlike scanning (which finds open ports) or enumeration (which extracts data), it matches discovered services and configurations against known vulnerability databases to identify specific CVEs that could be weaponized, with CVSS scoring ranking findings by severity for remediation priority. Module 5 accounts for approximately 10% of CEH v13 exam questions.
Key Concepts in Vulnerability Analysis
CVE and CVSS Frameworks: The Common Vulnerabilities and Exposures (CVE) database assigns unique identifiers to publicly disclosed vulnerabilities (e.g., CVE-2024-1234). The Common Vulnerability Scoring System (CVSS) scores severity from 0.0 to 10.0 based on attack vector, complexity, privileges required, user interaction, scope, and impact on confidentiality/integrity/availability; CVSS v3.1 is the current standard. The exam tests CVSS metric calculations and severity thresholds.
Network-Based vs Host-Based Scanning: Network-based scanners (Nessus, OpenVAS) find issues visible from the network — misconfigurations, outdated services, missing patches. Host-based agents (Qualys Agent, CIS CAT) run deep endpoint analysis: registry checks, file integrity, local service configurations, compliance posture. Know when each approach is appropriate.
Patch Management & Remediation: Findings only matter once remediated: test patches in staging, deploy by risk priority (critical first), verify fixes. Common exam scenarios cover patch SLAs (e.g., critical within 7 days, high within 30 days) and legacy systems that cannot be patched.
Risk Assessment & Prioritization: Risk assessment applies context — asset criticality, public exploit availability, compensating controls (WAF, IDS) — to turn raw findings into a prioritized plan. A 9.8 CVSS on a segmented internal system with no public exploit can rank below a 7.2 on an internet-facing web server under active exploitation.
Common Exam Mistakes in Module 5
Misplacing the CVSS band boundaries: 0.0–3.9 Low, 4.0–6.9 Medium, 7.0–8.9 High, 9.0–10.0 Critical — a 7.0 score is High, not Medium, and 9.0 opens the Critical band.
Reporting scanner output without verification: False positives come from misconfigured scanners and wrong version detection, so confirm every finding manually before it enters a remediation report. The opposite trap — a false negative the scanner missed — creates false confidence.
Mixing up who maintains what: CVE identifiers are assigned by MITRE, not OWASP or NIST. Distractors also swap tool roles: Burp Suite and Acunetix are web-focused, Qualys is the cloud platform, Nexpose (Rapid7) prioritizes by risk, OpenVAS is Nessus's open-source alternative.
Tools Used in Vulnerability Analysis
The scanners the CEH exam sorts into network-based, host-based and web-focused categories:
Nessus (Tenable): industry-standard commercial vulnerability scanner with a plugin library covering networks, web apps, databases and cloud
OpenVAS (Greenbone): the leading open-source vulnerability scanner — Nessus's standing alternative in multiple-choice sets
Qualys: cloud-based vulnerability management platform with continuous scanning and posture monitoring
Nexpose (Rapid7): enterprise scanner that prioritizes findings by risk, not raw counts
Burp Suite: web-application testing suite — proxies HTTP traffic and tests for XSS, SQL injection and authentication flaws
Acunetix: automated web vulnerability scanner in the same application-testing category as Burp Suite
Nikto: lightweight web server scanner that checks for known misconfigurations, outdated components and suspicious files
NSE vuln scripts: Nmap's vulnerability script category — quick checks layered onto a port scan without a dedicated scanner
Worked Example: Prioritizing Two Findings from One Scan
An authenticated Nessus scan of an authorized environment returns two findings: Finding A scores 9.8 (Critical) on an air-gapped test host with no public exploit code; Finding B scores 7.2 (High) on an internet-facing web server with a circulating proof-of-concept.
Ranking logic: patch Finding B first. CVSS measures inherent severity; remediation priority adds exposure, available exploits and compensating controls — so the internet-facing host outranks the segmented test box despite its lower score. Verify both findings to rule out false positives, then schedule Finding A against the normal high-severity SLA.
How to Study Vulnerability Analysis for the CEH v13 Exam
To study Module 5:
Memorize CVSS score ranges: 0.0–3.9 Low, 4.0–6.9 Medium, 7.0–8.9 High, 9.0–10.0 Critical — and each CVSS metric (AV, AC, PR, UI, S, C, I, A)
Hands-on: download Nessus Essentials (free), scan a Metasploitable 2 VM, find at least 5 vulnerabilities, look up their CVE IDs, verify their CVSS scores, and write a one-paragraph remediation recommendation for each
Frequently Asked Questions About Vulnerability Analysis
What is the difference between vulnerability assessment and penetration testing?
Vulnerability assessment is broad and automated: it identifies and lists security weaknesses across an environment without exploiting them. Penetration testing goes further, actively exploiting findings to demonstrate real-world impact. On the CEH exam, VA answers "what are the gaps?" while PT answers "how badly can they be exploited?" Both require written authorization; PT typically needs a more detailed scope and rules of engagement.
How does CVSS scoring work on the CEH exam?
CVSS v3.1 assigns a base score (0.0–10.0) calculated from eight metrics: Attack Vector (Network/Adjacent/Local/Physical), Attack Complexity (Low/High), Privileges Required (None/Low/High), User Interaction (None/Required), Scope (Unchanged/Changed), and impact on Confidentiality, Integrity, and Availability (None/Low/High). Exam questions give a vulnerability description and ask for the correct score or severity category. Tip: no user interaction, no privileges, network-exploitable with high impact on all three CIA dimensions scores 9.0 or above (Critical).