Skip to main content
Pricing
Sign inRequest demo

FedRAMP 20x Vulnerability Detail Report Example

Study three synthetic vulnerability records showing detection, internet reachability, likely exploitability, completed evaluation, and current rating fields.

0 downloads|ZIP (HTML + JSON)|2.8 KB

What's inside

  • Understand the fields around a detected vulnerability
  • Distinguish internet reachability from likely exploitability
  • Prototype vulnerability filtering and reviewer displays
  • Compare the example with current reporting requirements to find gaps

Best fit

  • Vulnerability-management teams
  • Security data engineers
  • Assessors and agency risk reviewers

Related topics

#FedRAMP 20x#Internet-Reachable Vulnerability (IRV)#JSON Example#Likely Exploitable Vulnerability (LEV)#Potential Agency Impact#Vulnerability Detail Report (VDR)#Vulnerability Reporting

Unlock this resource

Enter your work email to download FedRAMP 20x Vulnerability Detail Report Example.

What the report models

This Vulnerability Detail Report pair contains three synthetic findings for the example reporting period. Each record includes a provider tracking identifier, detection time and source, a description, internet-reachability evaluation, likely-exploitability evaluation, evaluation completion time, and a current numeric rating.

Those fields demonstrate an important FedRAMP 2026 distinction: internet reachability and likely exploitability are separate contextual evaluations. A vulnerable resource does not have to be directly internet-accessible to process a triggering internet-originated payload, and a scanner finding alone does not establish that exploitation is likely in the actual cloud service offering. The three records exercise different combinations of reachability, exploitability, and rating in JSON and HTML.

How to evaluate the example

Use the pair to prototype ingestion, validation, reporting, or reviewer experiences. A reader should be able to identify when a vulnerability was found, understand the provider's contextual evaluation, and follow changes in Potential Agency Impact over time.

Current Vulnerability Evaluation and Reporting rules call for additional decision context where applicable, including historical and current ratings, evaluated reductions, expected next reductions, overdue status, supplementary risk information, and final disposition. Treat this compact sample as a starting point for gap analysis, not a complete production report. Public vulnerability content also requires responsible-disclosure review.

Synthetic example and current status

The CVEs, identifiers, scanner results, components, reachability decisions, exploitability decisions, ratings, and remediation narratives in these 2026-07-27 files are fictional. They do not describe live Boundera vulnerabilities or production security. Refer to the official FedRAMP Marketplace record for current status.

Frequently asked questions

Is internet-reachable the same as directly internet-accessible?

No. The evaluation considers whether internet-originated input can reach and trigger the vulnerable condition, including through other components.

How does this differ from Accepted Vulnerability Information?

The detail report covers detected vulnerabilities other than accepted vulnerabilities; accepted records add the decision rationale for carrying the risk.

Are the CVEs in this file real Boundera findings?

No. Every finding and related technical detail is synthetic.

Put this resource to work

Turn this resource into a live FedRAMP workflow.

Boundera connects the evidence, gaps, POA&Ms, and continuous monitoring work behind the document.

Request demo

Related resources