Vulnerability Management TryHackMe Walkthrough

4 min readMar 12, 2024


TL;DR Walkthrough of the TryHackMe room Vulnerability Management.

— — Task 1 — -

No answer needed

— — Task 2 — -

The process encompassing vulnerability scanning and other factors, such as risk acceptance, is called?

Vulnerability Management

Is the overall objective of vulnerability management to increase an organisation’s risk exposure? (yea/nay)


— — Task 3 — -

What is the CVSS for CVE-2013–1048?


What is the Access Complexity for CVE-2013–1048?


With the fictional CVE-2023–2022, what would the CVE ID assign year be?


— — Task 4 — -

We have already scanned an Ubuntu machine; therefore, answer the following questions based on the scan report of LinuxAppTask task.

No answer needed

After scanning, what is the total number of medium-level vulnerabilities?


What is the severity score for the vulnerability “ICMP Timestamp Reply Information Disclosure”?


What is the operating system and the version number of the target machine?

Ubuntu 20.04

— — Task 5 — -

Download the LinuxAppTask report in PDF format. What is the severity rating of the vulnerability in the report, where the solution type is “Workaround”?


What is the solution type for the “TCP timestamps” vulnerability?


What is the CVE for “ICMP Timestamp Reply Information Disclosure”?


— — Task 6 — -

Create a ticket for resolving the “Cleartext Transmission of Sensitive Information via HTTP” vulnerability.

No answer needed

As a Security Engineer, the priority of a remediation ticket for a critical vulnerability must be (high/medium/low)?


— — Task 7 — -

The process of listing vulnerabilities as per their order of priority is called?

Prioritise vulnerabilities [TryHackMe’s spelling, “Prioritize vulnerabilities” won’t get a go on THM]

Which phase entails updating and strengthening resilience plans and restoring any compromised capabilities or services caused by a cybersecurity event?


I have read the details regarding all five phases of the NIST CSF.

No answer needed

— — Task 8 — -

No answer needed

Updating OpenVAS

I had to run the below to update OpenVAS and get it working right again for this room.

pg_dropcluster --stop 16 main
pg_upgradecluster 15 main
pg_dropcluster --stop 15 main

apt install postgresql-16-pg-gvm
sudo runuser -u postgres -- /usr/share/gvm/create-postgresql-database
sudo runuser -u _gvm -- gvmd --migrate

sudo gvm-check-setup
sudo gvm-start


Oddly TryHackMe asks which vulnerability had “Workaround” as the solution, but all 3 listed “Mitigation” in OpenVAS. Either THM was wrong, which happens sometimes, or it’s because I updated OpenVAS right before doing this room and THM was running an older version when they setup the room.

It’s rare that this mismatch in results and ‘the right answer’ on THM differ. Just be aware of this one in case you’re knocking out the room.

