Ethiack Docs

Vulnerability Status Flow

Understanding the lifecycle of vulnerabilities and available status transitions

In this section we aim to identify and describe the various available status through which a vulnerability can pass. It is important to understand which transitions are possible, what the status mean, and what the range of action of the Ethiack team and its customers is in these status.

The existing status that can be found on the Ethiack portal at the moment are as follows:

Status

Open: This is a vulnerability that has yet to be evaluated by Ethiack, i.e. it has been detected, it seems to be valid, but it still needs to be evaluated by the Ethiack team (this status is used more often in Expert Pentests).

Informative: A vulnerability that has been identified and analyzed, but does not have a significant impact. It is usually used to identify bad security practices or minor system nonconformities.

Duplicate: Assigned when a vulnerability has been identified and is valid, but has already been identified before.

Triaged: A vulnerability that has been identified and validated by Ethiack. It already has a severity rating and a CVSS score to assess its severity.

Invalid: Usually assigned to vulnerabilities that are false positives or not valid for that context.

Accepted: Refers to an Accepted Risk — a vulnerability that has been identified and assessed by Ethiack, but which the client is aware of and accepts the inherent risk without immediate remediation.

Fixed: Signals a vulnerability that has been fixed on your side.

The diagram below shows the valid transition paths from when a vulnerability arises until it is reported as Fixed:

Status flow diagram

Important: In the retesting phase, a vulnerability marked as "Fixed" can return to "Triaged" status if it has not been fixed correctly.