A vulnerability is a weakness that can be exploited. It might be a software bug, a misconfiguration, a design flaw, or a human habit. The Common Vulnerabilities and Exposures database tracks known software flaws with unique identifiers. CVE-2021-44228, known as Log4Shell, was a vulnerability in a widely used logging library. It allowed remote code execution on millions of servers. Attackers exploited it within hours of disclosure. Patches came fast. Many systems stayed unpatched for months.
Not all vulnerabilities are software bugs. A server with default credentials is vulnerable. A cloud storage bucket set to public is vulnerable. An employee who reuses passwords is vulnerable. A network without segmentation is vulnerable. The definition is broad because the attack surface is broad. Vulnerabilities are scored using the Common Vulnerability Scoring System. CVSS rates severity from 0 to 10 based on exploitability and impact. A 10 is critical. A 3 is low. The score helps prioritize patching. But the score is not the whole story. A critical vulnerability in an isolated system matters less than a medium one in an internet-facing server. Context determines priority. The vulnerability is only half the equation. The other half is whether anyone can reach it.
Vulnerability sources
- Software bugs — coding errors that allow exploitation
- Misconfigurations — settings that weaken security
- Design flaws — architectural weaknesses
- Human factors — weak passwords, poor habits
- Supply chain — vulnerabilities in third-party components
A vulnerability is a door left unlocked. A threat is someone trying the handle. Risk is what happens when they get in.
Comments
No comments yet. Be the first to share a thought.
Leave a comment