Greenbone / OpenVAS · XML export
Greenbone / OpenVAS vulnerability reports
Greenbone exports frequently identify findings by OID with no structured CVE references attached. Varaxon Scan Hub reports that state honestly.
Data-quality state: CVE-based assessment unavailable
When an export contains no structured CVE references, the report says CVE-based assessment could not be performed. That is not a statement that the environment is clean — it is a statement about the data.
How Greenbone exports are handled
- Findings are preserved as reported. OIDs, names, severity fields and scanner output are carried into the report unchanged.
- Coverage is stated, not implied. Every section says whether CVE data was present for the findings it covers.
- OID-to-CVE enrichment is optional and server-side. Where enrichment is applied, it is labelled as enrichment and separated from what the export itself asserted. It never runs in your browser.
- Conflicts are quarantined. Two different CVE sets for the same finding are both retained and marked Unknown until resolved.
Using Tenable instead? See how Nessus exports are handled.

