Troubleshooting Tip: Understanding high severity for LW_VULN_103, a known security vulnerability when CVEs are medium or low
| Description | This article describes why the built-in Lacework host vulnerability policy LW_VULN_103 – Known Security Vulnerability generates High severity alerts even when the associated CVEs are rated as Medium or Low. |
| Scope | All environments using the Lacework host vulnerability policy LW_VULN_103. |
| Solution | The LW_VULN_103 – Known Security Vulnerability policy is configured by design to generate High severity alerts regardless of the individual CVE severities included in the alert. This approach highlights that a host is actively running software with known vulnerabilities, which is treated as a high-priority risk.
Policy behavior:
Key points:
Because the policy severity is set to High, any alert generated by LW_VULN_103 will appear as High, even if all CVEs in the alert are Medium or Low. Customizing Policy Behavior
CVE Severity INCLUDE High,Critical AND Package active INCLUDE 1 Note: Do not include spaces after the comma.
Example use cases:
|