Vulnerability Management

CVE ManagerNew

Closes the loop between vulnerability discovery and remediation — import CVEs directly from HakScout data, assign them to owners, track status, and automatically mark them resolved when they disappear from your environment.

CVE Manager

CVE assignment, tracking, and remediation workflow

What it does

Key capabilities

HakScout Import

Pulls all CVEs detected by HakScout OS and service scanning with one click — deduplicates automatically and derives priority from CVSS score.

User Assignment

Assign any CVE to a specific team member with a due date and priority level — full ownership tracking from open to closure.

Auto-Remediation Detection

Automatically marks CVEs as Remediated when they no longer appear in your active HakScout scan data — no manual status updates needed.

Overdue Tracking

Highlights overdue CVEs in red and provides dashboard visibility into outstanding remediation by owner and severity.

Severity Dashboard

Executive dashboard showing CVEs by severity (Critical/High/Medium/Low), status distribution, and recent activity.

NVD Integration

Direct links to the NIST NVD record for every CVE — full technical detail, CVSS vector, and reference links one click away.

Highlights

Why CVE Manager?

  • One-click import from HakScout CVE detection data
  • CVSS-derived priority — Critical ≥9.0, High ≥7.0, Medium ≥4.0
  • Auto-remediation detection on next HakScout scan
  • Per-CVE owner assignment with due date and SLA tracking
  • Accepted Risk status for risk-accepted findings
Included in OneView

CVE Manager is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.

24/7 Support Available
Phone: +27 060 984 1210
FAQs

Frequently asked questions

After a HakScout network scan completes, CVE Manager offers a one-click import of all CVEs detected in that scan. The import deduplicates against existing open CVEs, assigns CVSS-derived priority automatically (Critical ≥9.0, High ≥7.0, Medium ≥4.0, Low below), and presents newly discovered CVEs ready for owner assignment and SLA tracking.

When a CVE marked as open in your register no longer appears in the latest HakScout scan data for the affected asset, CVE Manager automatically transitions the CVE to a Remediated status — without requiring a manual status update. This ensures your register accurately reflects actual remediation progress rather than relying on analyst updates.

Yes. CVE Manager supports an Accepted Risk status for findings where the risk has been formally accepted — for example, a CVE with no available patch, or where compensating controls make the risk tolerable. Accepted risk findings remain in the register with the acceptance rationale recorded, satisfying auditor requirements for documented risk decisions.

Each CVE gets an assigned owner and a due date based on its priority — typically 30 days for Critical, 60 for High, 90 for Medium. Overdue CVEs are highlighted in red in the dashboard and flagged for escalation. This SLA tracking provides documented evidence of timely remediation that PCI DSS, ISO 27001, and cyber insurers require.

See CVE Manager in action

Request a personalised demo and we'll show you exactly how CVE Manager works within your environment.