Active
--:--:-- UTCSyed Dayaan Shah
← Back to case filesCase · VULN-007
Vulnerability ManagementSeverity · high60-day program

60-day CVE remediation program with Nessus

Inherited 127 open critical CVEs and no remediation cadence. Built a CVSS+EPSS prioritized program on top of authenticated Nessus scans and PDQ Deploy automation. Hit zero-critical in 54 days.

Evidence · Program dashboard · criticals to zeroLIVE
Tenable.io · Vulnerability Overview

Critical

0

High

12

Medium

84

Assets scanned

312

Critical CVE count · 60-day trend

1270

Criticals closed

127

MTTP

6 days

Days to zero-critical

54

Endpoints

200+

[01]Objective

Bring a mid-size client environment from a 127-critical backlog down to zero criticals in 60 days.

[02]Live Lab · CVE triage board
Interactive · runs in your browser
Formula: CVSS × EPSS × log₂(assets+2)
  • 01

    CVE-2024-3400 · PAN-OS command injection

    C10.0E96A2
  • 02

    CVE-2024-21412 · SmartScreen bypass

    C8.1E72A148
  • 03

    CVE-2024-1709 · ConnectWise auth bypass

    C10.0E94A4
  • 04

    CVE-2023-46805 · Ivanti Connect Secure auth bypass

    C8.2E88A3
  • 05

    CVE-2024-27198 · TeamCity auth bypass

    C9.8E81A1
  • 06

    CVE-2024-24919 · Check Point info disclosure

    C7.5E66A2
  • 07

    CVE-2024-3273 · D-Link NAS RCE

    C9.8E42A0
  • 08

    CVE-2023-4966 · Citrix Bleed

    C9.4E98A1
  • 09

    CVE-2024-21762 · Fortinet SSL-VPN OOB write

    C9.6E79A1
  • 10

    CVE-2024-6387 · regreSSHion OpenSSH RCE

    C8.1E31A62
  • 11

    CVE-2023-38831 · WinRAR archive spoofing

    C7.8E71A190
  • 12

    CVE-2024-30078 · Windows Wi-Fi driver RCE

    C8.8E24A200
[03]Stack · Tools & Platforms

Tools

  • Tenable Nessus
  • OpenVAS
  • PDQ Deploy
  • PowerShell
  • CVSS + EPSS

Platforms

  • Windows 10/11
  • Windows Server 2019/2022
  • Ubuntu 22.04
[04]Method
  1. 01

    Enabled authenticated scans — surfaced 41% more findings.

  2. 02

    Prioritized backlog by CVSS × EPSS × asset criticality; weekly sprints.

    Fig · 02 · Remediation board · sprint viewLIVE
    Jira · VULN boardSprint 42

    To Patch (3)

    CVE-2024-38178 · Edge
    CVE-2024-43451 · Windows
    CVE-2024-49138 · CLFS

    In Progress (2)

    CVE-2024-38063 · TCPIP
    CVE-2024-30078 · Wi-Fi

    Verify (2)

    CVE-2024-21412 · Defender
    CVE-2024-26169 · WERKernel

    Closed (4)

    CVE-2023-36884
    CVE-2024-21334
    CVE-2024-37085
    CVE-2024-38014
  3. 03

    PowerShell + PDQ deployment for Zoom, 7-Zip, Chrome, Java.

  4. 04

    Verified with re-scans; closed only after two clean scans.

    Fig · 04 · Compliance table · after re-scanLIVE
    Patch compliance reportPost-remediation scan
    Host groupProgressCompliance
    Domain controllers
    100%
    File servers
    100%
    Workstations · finance
    96%
    Workstations · engineering
    88%
    Legacy print servers
    72%

    Overall fleet compliance · 94.2% ↑ from 71.8%

[05]Outcome

127 critical CVEs closed, MTTP down to 6 days, weekly exec dashboard live.

[06]Lessons learned
  • Unauthenticated scans lie by omission — always credentialed.
  • EPSS in the priority formula reorders which critical you patch first.

Next case · IR-042

Ransomware response — a branching 60-minute drill

Open →