<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vulnerabilities report in Prisma Cloud in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/vulnerabilities-report-in-prisma-cloud/m-p/587797#M1224</link>
    <description>&lt;P&gt;Hi Stumiki,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your reply.&amp;nbsp;&lt;BR /&gt;I realized that even when I do what you suggested (checking each individual CVE) it still doesn't show me all vulns for specific CVE ID.&amp;nbsp;&lt;BR /&gt;To give you an example - if I run a query &lt;STRONG&gt;FIND VULNERABILITY WHERE ASSET TYPE IS DEPLOYED IMAGE&lt;/STRONG&gt;) , and I see the line of an exemplary record I have:&lt;BR /&gt;&lt;BR /&gt;| CVE | SEVERITY | CVSS | RISK FACTORS | IMPACTED ASSETS |&lt;BR /&gt;&lt;BR /&gt;What I am after should be in I IMPACTED ASSETS | column but it is not.&amp;nbsp;&lt;BR /&gt;The column displays specific CVEs with the affected number of assets, not necessarily number of of vulnerabilities.&amp;nbsp;&lt;BR /&gt;If exemplary CVE-ABC-2024 is present in the runtime of VM1, above report would print 1.&amp;nbsp;&lt;BR /&gt;If however, there may be a case that preceding VM1, having in its runtime 12 packages that are vulnerable to that CVE, number would be slightly different.&lt;BR /&gt;Is there any workaround to get the detailed list of total vulnerabilities ?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Kociou&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 23 May 2024 15:20:23 GMT</pubDate>
    <dc:creator>M.Kotlowski</dc:creator>
    <dc:date>2024-05-23T15:20:23Z</dc:date>
    <item>
      <title>Vulnerabilities report in Prisma Cloud</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/vulnerabilities-report-in-prisma-cloud/m-p/585619#M1217</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope you are well.&amp;nbsp;&lt;BR /&gt;The reason why I am writing this one is that I need help of some PRISMA practitioners.&amp;nbsp;&lt;BR /&gt;With all of the shiny features being present in the platform, I realized I am unable to get relevant and simple information.&amp;nbsp;&lt;BR /&gt;&lt;U&gt;&lt;BR /&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;I need PRISMA to tell me the amount of vulnerabilities seen in the system for specific CVSS, and discovered X days ago.&amp;nbsp;&lt;BR /&gt;When I go to&amp;nbsp;&lt;STRONG&gt;Investigate&amp;nbsp;&lt;/STRONG&gt;module, prepare corresponding query [&lt;EM&gt;FIND Vulnerability WHERE CVSS score &amp;gt;=7 Age(Days) &amp;lt;7&lt;/EM&gt; ] and hit on Search I got some findings.&amp;nbsp;&lt;BR /&gt;What PRISMA is telling me is number of detected records (or CVEs) not vulnerabilities.&amp;nbsp;&lt;BR /&gt;Ergo, to get the number of vulnerabilities I need to export CSV, and sum all of the impacted assets to get the real number of them.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is there an easier way than this to have all of the vulnerabilities listed for specific CVSS for specific period?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 09:42:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/vulnerabilities-report-in-prisma-cloud/m-p/585619#M1217</guid>
      <dc:creator>M.Kotlowski</dc:creator>
      <dc:date>2024-05-02T09:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerabilities report in Prisma Cloud</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/vulnerabilities-report-in-prisma-cloud/m-p/586704#M1218</link>
      <description>&lt;P&gt;Hello Kociou,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the query.&amp;nbsp;&lt;SPAN&gt;We don’t have a way just to bulk export all the Vulnerabilities for all the affected CVEs yet based on your query.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="1715721120.877789" class="c-virtual_list__item" tabindex="-1" role="listitem" aria-setsize="-1" data-qa="virtual-list-item" data-item-key="1715721120.877789"&gt;
&lt;DIV class="c-message_kit__background c-message_kit__background--hovered p-message_pane_message__message c-message_kit__message" role="presentation" data-qa="message_container" data-qa-unprocessed="false" data-qa-placeholder="false"&gt;
&lt;DIV class="c-message_kit__hover c-message_kit__hover--hovered" role="document" aria-roledescription="message" data-qa-hover="true"&gt;
&lt;DIV class="c-message_kit__actions c-message_kit__actions--above"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__left" role="presentation"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;So, after running the query you will get the results, for every row in the table, you need to download the CSV file for that specific vulnerability (CVE) individually.&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;The bulk download feature is going to be available in the near future.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 14 May 2024 21:50:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/vulnerabilities-report-in-prisma-cloud/m-p/586704#M1218</guid>
      <dc:creator>stumiki</dc:creator>
      <dc:date>2024-05-14T21:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerabilities report in Prisma Cloud</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/vulnerabilities-report-in-prisma-cloud/m-p/587797#M1224</link>
      <description>&lt;P&gt;Hi Stumiki,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your reply.&amp;nbsp;&lt;BR /&gt;I realized that even when I do what you suggested (checking each individual CVE) it still doesn't show me all vulns for specific CVE ID.&amp;nbsp;&lt;BR /&gt;To give you an example - if I run a query &lt;STRONG&gt;FIND VULNERABILITY WHERE ASSET TYPE IS DEPLOYED IMAGE&lt;/STRONG&gt;) , and I see the line of an exemplary record I have:&lt;BR /&gt;&lt;BR /&gt;| CVE | SEVERITY | CVSS | RISK FACTORS | IMPACTED ASSETS |&lt;BR /&gt;&lt;BR /&gt;What I am after should be in I IMPACTED ASSETS | column but it is not.&amp;nbsp;&lt;BR /&gt;The column displays specific CVEs with the affected number of assets, not necessarily number of of vulnerabilities.&amp;nbsp;&lt;BR /&gt;If exemplary CVE-ABC-2024 is present in the runtime of VM1, above report would print 1.&amp;nbsp;&lt;BR /&gt;If however, there may be a case that preceding VM1, having in its runtime 12 packages that are vulnerable to that CVE, number would be slightly different.&lt;BR /&gt;Is there any workaround to get the detailed list of total vulnerabilities ?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Kociou&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 15:20:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/vulnerabilities-report-in-prisma-cloud/m-p/587797#M1224</guid>
      <dc:creator>M.Kotlowski</dc:creator>
      <dc:date>2024-05-23T15:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerabilities report in Prisma Cloud</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/vulnerabilities-report-in-prisma-cloud/m-p/588295#M1230</link>
      <description>&lt;P&gt;Hello Kociou,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For getting the Impacted assets - Navigate to Investigate -&amp;gt; Query -&amp;gt; FIND Vulnerability, where CVE-ID is CVE-ABC-2024 -&amp;gt; Search the query for results. Under the results click on Vulnerabilities, CVE Icon -&amp;gt; View Details. You will now be able to see a tab with Impacted Assets for that specific CVE-ABC-2024, you have an option to download the CSV for this. &lt;BR /&gt;You will have another tab with Distro Information that will provide you with the packages that were impacted for that specific CVE-ABC-2024. You will have an option to download the CSV for individual packages results shown.&lt;/P&gt;
&lt;P&gt;For getting the detailed list of total vulnerabilities for a specific CVE-ABC-2024. Navigate to Monitor -&amp;gt; Vulnerabilities -&amp;gt; Vulnerability Explorer -&amp;gt; Filter by a CVE ID for getting the total list of vulnerabilities and an option to export a CSV file.&lt;/P&gt;
&lt;P&gt;For getting the detailed list of total vulnerabilities. Navigate to Monitor -&amp;gt; Vulnerabilities -&amp;gt; Images -&amp;gt; Download CSV.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 19:49:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/vulnerabilities-report-in-prisma-cloud/m-p/588295#M1230</guid>
      <dc:creator>stumiki</dc:creator>
      <dc:date>2024-05-29T19:49:58Z</dc:date>
    </item>
  </channel>
</rss>

