Vulnerability Assessment vs Penetration Testing
|
Aspect |
Vulnerability Assessment |
Penetration Testing |
|
Goal |
Find vulnerabilities |
Exploit vulnerabilities |
|
Depth |
Wide, shallow scan |
Narrow, deep attack |
|
Risk |
Low risk to systems |
Higher risk — active exploitation |
|
Output |
List of vulnerabilities with severity |
Proof of exploitation + impact |
|
Frequency |
Regular (monthly/quarterly) |
Periodic (annually or on-demand) |
CVSS Score Explained
- CVSS (Common Vulnerability Scoring System) scores vulnerabilities from 0.0 to 10.0
- Critical: 9.0–10.0 | High: 7.0–8.9 | Medium: 4.0–6.9 | Low: 0.1–3.9
- CVE (Common Vulnerabilities and Exposures) — Unique ID for each known vulnerability
- NVD (National Vulnerability Database) — Repository of all CVEs with CVSS scores
Lab: OpenVAS Scan
- Install OpenVAS on Kali: apt install openvas && gvm-setup
- Access the web interface at https://127.0.0.1:9392
- Create a new scan task targeting your test VM
- Review the report and categorize findings by severity