correlate_devices
Find CVEs affecting specific devices at their exact firmware version. Send vendor, product, and version to get prioritized findings, fix plans, and advisories without needing CPE.
Instructions
Find the CVEs that affect specific devices at their exact firmware or software version. Use this for any specific device and firmware. Send vendor, product and version exactly as the inventory says; no CPE is needed. Returns, per device: how it resolved, data coverage, an honest assessment, warnings, needs_review, result_hash (keep it for check_changes), the fix plan, and the top findings in priority order (known-exploited and confirmed first). Each finding gives the affected range with its source, the fix, advisory guidance and vendor advisories: cite the range source and the vendor advisory when explaining it. Report needs_review and partial coverage honestly and never call an empty, unresolved or partial result clean. Never send host names, IP or MAC addresses, user names or site names; such fields are stripped and listed under privacy.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| assets | Yes | Devices to check: vendor, product, version and an optional neutral asset_id. | |
| max_findings | No | Findings returned per device, highest priority first. | |
| confirmed_only | No | Only CVEs confirmed for this version by a version range. | |
| fix_available_only | No | Only CVEs with a fix available. | |
| known_exploited_only | No | Only known-exploited CVEs. |