How many of your assets share the same affected product, shown beside the published impact severity of each record. No downstream reach is inferred.
Current, non-demo canonical findings for the active organisation and scan scope. Every row is backed by evidence collected from your own assets.
0 product group(s) with confirmed findings. Asset counts are counted, never inferred.
Powered by: public.canonical_findings grouped by asset and canonical product (environment mode) · public.cves via fetchCves for CIA impact and attack vector
Rule: Concentration = distinct affected assets per canonical product, counted once per asset + product + version + CVE. Impact severity = 0.5 × CIA impact + 0.3 × exploitability + 0.2 × attack vector, shown separately from asset counts.
Previously called “Blast Radius”. Renamed because the underlying evidence does not support that stronger claim.
Concentration = the number of distinct assets carrying a confirmed finding for a canonical product. Each asset + product + version + CVE counts once.
Impact severity = 0.5 × CIA impact + 0.3 × exploitability + 0.2 × attack vector, read from the published CVSS vector. It is displayed separately from the asset count and is never multiplied by it.
Not known here: network reachability between assets (Not assessed), dependency and group membership (Not modeled), lateral movement (Not modeled). A CVSS vector is not evidence of downstream reach.