Every column available on the Analyze grid, grouped the way the grid colour-bands them. Use the toolbar’s column controls to show and hide them; your choices are saved per view.
| Column |
What it contains |
| Host IP |
The scanned host’s IP address. |
| Hostname |
The host name from the scan. Nessus takes the best name it has — a resolved hostname, a NetBIOS name, or the first part of the DNS name. |
| Host Description |
Free-text description of the host, where the scan or your baseline supplied one. |
| MAC Address |
The host’s hardware address. A host can report several. |
| DNS Name |
The fully-qualified DNS name. |
| NetBIOS |
The NetBIOS name. |
| OS |
The operating system as reported by the scan. |
| Column |
What it contains |
| Nessus Severity |
The severity exactly as Nessus assigned it: Critical, High, Medium, Low, Information. |
| DOD Severity |
The severity NESSviewer calculates from your settings in Options (section 11.1). |
| STIG Severity |
The STIG severity carried by the plugin: I, II or III. Blank where the plugin has none. |
| CVSS Base Score |
The CVSS version 2 base score. |
| CVSS3 Base Score |
The CVSS version 3 base score — the one to use when both are present. |
| CVSS3 Temporal Score |
The CVSS v3 score adjusted for exploit maturity and remediation availability. |
| CVSS Vector |
The CVSS v3 vector string, describing how the score was arrived at. |
| Exploit Available |
true when a public exploit is known to exist. |
| Exploitability Ease |
The plugin’s own words on how easily it can be exploited. |
| Exploit Framework |
The exploit framework or module name where one is known. |
| ExploitNoURL |
The same value without link formatting. |
| CISA KEV |
Yes when one of the finding’s CVEs is in the CISA Known Exploited Vulnerabilities catalog — confirmed exploitation in the wild. |
| CISA KEV Due Date |
The BOD 22-01 remediation deadline for that KEV entry. |
| KEV Ransomware |
Known when the KEV entry has been linked to ransomware campaigns. |
| Unsupported by Vendor |
Yes when the product is end-of-life. There will be no patch; the fix is to replace or isolate it. |
| Column |
What it contains |
| PluginID |
The Nessus plugin number. Links to the plugin’s page on Tenable’s site. |
| PluginIDNoURL |
The bare plugin number. This is the key used to match findings to your POA&M and remediation plan. |
| Plugin Name |
The plugin’s title — the short statement of what was found. |
| Description |
The full write-up of the vulnerability. |
| Synopsis |
A one-line summary. |
| Solution |
What the plugin recommends doing about it. |
| PluginOutput |
The evidence gathered on this specific host — the file version found, the setting read, the banner returned. |
| External Reference |
Cross-references carried by the plugin, including IAVA, IAVB and IAVT advisory numbers. |
| See Also |
Reference links from the plugin — vendor advisories and bulletins. |
| CVE |
The CVE identifiers for this finding. Links to the entry at NIST’s National Vulnerability Database. |
| CWE |
The weakness type, such as CWE-79 Cross-site Scripting. |
| CWE Details |
The weakness name with its consequences and mitigations, from the built-in CWE data. |
| CPE |
The standardised product identifiers involved in the finding. |
| Column |
What it contains |
| Publication Date |
When the plugin was published — the point from which finding age is measured. |
| Days Since Publication |
Whole days since that date. This drives the aging table and the POA&M aging rules. |
| Modification Date / Days Since Modification |
When the plugin was last updated, and how long ago that was. |
| Vuln Publication Date |
When the vulnerability itself was made public. |
| Patch Publication Date |
When the vendor published a fix. |
| Scan Date |
When the scan finished on this host. |
| Report Name |
The report name recorded inside the scan file. |
| Filename/Path |
The scan file this row came from. |
| Scan Info |
The scanner’s own record of how the scan was configured. |
| Credentialed |
Whether this host was scanned with working credentials. If this is not true, treat the absence of findings on this host with suspicion. |
| Port Range |
The port range the scan policy was configured with. |
| Port, Protocol, Service |
Where on the host the finding applies. |
| Column |
What it contains |
| POA&M Status (eMASS) |
The status of the matching POA&M item, or No POA&M Loaded / Not on POA&M / On POA&M. |
| POA&M Raw Severity |
The raw severity recorded on the POA&M item. |
| POA&M Devices Affected |
The hosts listed on the matching POA&M item or items. |
| POA&M Item ID |
The item identifier as it appears in eMASS. |
| POA&M eMASS Link ID |
The internal record identifier that powers the Open in eMASS link. |
| POA&M Required |
Yes when the finding is older than the aging threshold for its severity, No when it is still inside the window, blank when the rule is off or there is no publication date. |
| Remediation Action |
The planned action from your remediation plan. |
| Remediation Category |
The plan’s category for that action. |
| Remediation ECD |
The estimated completion date. |
| Remediation POC |
Who owns it. |
| Remediation Details |
Free-text detail from the plan. |
| Mitigation |
Compensating controls recorded in the plan. |