Vulnerability Assessment vs Penetration Testing

Aspect

Vulnerability Assessment

Penetration Testing

Goal

Find vulnerabilities

Exploit vulnerabilities

Depth

Wide, shallow scan

Narrow, deep attack

Risk

Low risk to systems

Higher risk — active exploitation

Output

List of vulnerabilities with severity

Proof of exploitation + impact

Frequency

Regular (monthly/quarterly)

Periodic (annually or on-demand)

CVSS Score Explained

  • CVSS (Common Vulnerability Scoring System) scores vulnerabilities from 0.0 to 10.0
  • Critical: 9.0–10.0 | High: 7.0–8.9 | Medium: 4.0–6.9 | Low: 0.1–3.9
  • CVE (Common Vulnerabilities and Exposures) — Unique ID for each known vulnerability
  • NVD (National Vulnerability Database) — Repository of all CVEs with CVSS scores

Lab: OpenVAS Scan

  1. Install OpenVAS on Kali: apt install openvas && gvm-setup
  2. Access the web interface at https://127.0.0.1:9392
  3. Create a new scan task targeting your test VM
  4. Review the report and categorize findings by severity