Why is a CVE Showing as N/A?

Objective

To explain why specific Common Vulnerabilities and Exposures (CVEs) or Vulnerability Sync data may display as N/A or Unknown in the Automox Console or Vulnerability Scanner reports.

Overview

Automox correlates endpoint inventory with vulnerability intelligence feeds to identify missing patches and security risks. However, not all published CVEs will map to an actionable patch or an identified severity score within the Automox platform. When a CVE displays as N/A or Unknown, it indicates that the vulnerability either lacks vendor scoring data, is non-actionable via software patching, or is not applicable to your managed endpoints.

CVSS Severity Mapping Reference

Automox calculates vulnerability severity using the Common Vulnerability Scoring System (CVSS) standards (both CVSS v2 and CVSS v3). When an update addresses multiple CVEs simultaneously, Automox assigns the highest CVSS score among the bundled CVEs to determine the overall package severity.

Severity Rating CVSS v2 Score Range CVSS v3 / v3.1 Score Range
Critical 10.0 9.0 – 10.0
High 7.0 – 9.9 7.0 – 8.9
Medium 4.0 – 6.9 4.0 – 6.9
Low 0.0 – 3.9 0.1 – 3.9
Unknown / N/A Unscored or Incomplete Data Unscored or Incomplete Data

ℹ️ Note: If a CVE has not yet been assigned a CVSS score by NVD/MITRE, or if Automox lacks sufficient vendor metadata at the time of ingest, the score defaults to Unknown.

Primary Reasons CVEs Show as "N/A" or "Unknown"

If a CVE is flagged as N/A or Unknown in your console or Vulnerability Sync reports, it typically falls under one of the following five scenarios:

  1. No Managed Devices Are Vulnerable: The CVE applies to an operating system, application version, or hardware architecture that does not exist on any active device within your Automox organization.

  2. The Update Has Been Superseded: The specific patch originally tied to the CVE has been replaced by a newer cumulative update, rendering the individual vulnerability non-applicable.

  3. Unsupported Third-Party Software: The CVE impacts a software application not currently included in the Automox Third-Party Software Support catalog.

  4. Hardware or Firmware Vulnerability: The CVE targets hardware, BIOS/UEFI, or system firmware updates, which cannot be remediated via standard operating system patch channels.

  5. Configuration-Based Vulnerability: The CVE requires manual configuration changes, registry modifications, or group policy adjustments rather than a software package installation. (These can often be remediated using custom Automox Worklets).

Verification & Recommended Actions

 

1.Check Endpoint Applicability:

Review the affected device list in Vulnerability Sync to confirm whether any online endpoints actively run the software version impacted by the CVE.

2.Verify Software Catalog Support:

Consult Third-Party Software Support to verify if the impacted application is natively supported for automated patching by Automox.

3.Deploy Worklets for Configuration Issues:

If the CVE relates to a system configuration setting or registry tweak, deploy a targeted Worklet policy to remediate the setting across your fleet.

Was this article helpful?
0 out of 0 found this helpful