Skip to main content

Network Vulnerabilities (CVE) (server)

The server responds according to the CVE scenario. The server does not have Targets or CPS settings. Its CVE set and mode must match the client's.

  1. Receiver — same as for the HTTP server plugin.
  2. CVE settings — same as on the client: attack/FP mode, first/all scenarios, CVE selection, and step timeout (blocked_timeout). For details on interpreting outcomes (completed / blocked_*), see Network Vulnerabilities (CVE).
  3. Session settings — timeout only.
  4. IP header (L3) — same as for the HTTP server plugin.
  5. TCP header (L4) — same as for the HTTP server plugin.
  6. TLS settings — same as for the HTTP server plugin.
  7. Duration — same as for the HTTP server plugin.
  8. Network tunnels (optional).