Findings
Every finding ranked by dollar loss. Click filters to re-sort.
Total Annual Loss Exposure
$1,500,000
Across 3 visible findings
Sum of per-finding ALE (mode)
Sum of per-finding ALE (mode)
critical KEV
XZ Utils backdoor (CVE-2024-3094) in OpenSSH
Malicious code injected into XZ Utils 5.6.0/5.6.1 can bypass SSH authentication on internet-facing hosts. KEV-listed.
Vulnerability Scan·nw-jumphost-01.northwind.internal·3 days ago
$832,000
$520,000 – $1,400,000
critical KEV
SMBv3 RCE (CVE-2020-0796 / SMBGhost)
Unauthenticated remote code execution in SMBv3 on a Windows Server 2019 host accepting external traffic.
Vulnerability Scan·nw-files-03.northwind.internal·5 days ago
$512,000
$280,000 – $980,000
high KEV
Log4Shell (CVE-2021-44228) in web service
Vulnerable Log4j 2.14.1 detected via authenticated scan on internal order-api service.
Vulnerability Scan·nw-order-api.northwind.internal·18 days ago
$156,000
$75,000 – $310,000