App navigation: Risk → Vulnerability
The Vulnerability module tracks security weaknesses identified across your asset inventory – whether discovered by a scanner, manually assessed, or imported from a third-party tool. Vulnerabilities are scored using the industry-standard CVSS scale and linked to risks via the ATVEC methodology.
Screen Layout #
Navigate to Risk → Vulnerability to open the Vulnerability Inventory screen. The summary panel shows total vulnerability counts and a breakdown by CVSS severity (Critical, High, Medium, Low).
[Screenshot: Vulnerability Inventory screen showing CVSS severity breakdown]
Creating a Vulnerability #
Select + on the toolbar. The Vulnerability Action dialog offers four options:
- Create Manually – enter Title, Description, CVSS Severity score, Affected Assets, Status, and Owner.
- Import from File – bulk import using a file upload.
- Import from NVD – pull vulnerability data from the NIST National Vulnerability Database.
- Import from Nessus – connect to your Nessus integration (configured via Admin → System → Integrations). ClearGRC creates records pre-populated with scan metadata and CVSS scores.
[Screenshot: Vulnerability Action dialog]
Linking Vulnerabilities to Risks #
Vulnerabilities can be linked to Risk Register entries via the ATVEC Mapping wizard step, providing a traceable chain from the specific vulnerability to the formal risk it contributes to.
Tip: Filter the Vulnerability Inventory by Critical and High CVSS severity to prioritize remediation of the most dangerous weaknesses first.
