In Qualys VMDR, what is a QID, and why is it not the same thing as a CVE?
answer
- the KnowledgeBase entry, not the advisory
- one detection, possibly several CVEs
- Confirmed, Potential, Information
- Qualys severity versus your severity
- inventory QIDs carry no CVE
basics
~20 sA QID (Qualys ID) is the number of one detection in the Qualys KnowledgeBase. A CVE names a published flaw; a QID is Qualys's test and verdict, may list several CVEs, and can carry none at all.
solid answer
~40 sA **QID** is the unique Qualys ID of one detection in the Qualys **KnowledgeBase**; Qualys maintains more than 100,000 of them. It is the unit everything in VMDR counts: a finding is "QID X on asset Y". A CVE is an industry identifier for a published flaw, while a QID is Qualys's own check plus its result, so one QID can list several CVEs in `vulnerabilities.vulnerability.cveIds`, and many QIDs have none. Each finding has a detection type (**Confirmed**, **Potential** or **Information**), a Qualys severity from 1 to 5 that you can override with your own severity, and a Qualys Detection Score. Information-gathered QIDs such as 45141 (installed packages on Unix and Linux) record facts, not flaws. You can also write **custom QIDs** for in-house software.
go deeper
Recall that a QID is a KnowledgeBase detection, not a CVE, and name the three detection types: Confirmed, Potential and Information.
Explain the mapping: zero, one or several CVEs per QID, the highest-scoring CVE driving QDS, and Qualys severity beside customer severity.
Show you use the detection type and information-gathered QIDs in triage and reporting, and when a custom QID fits in-house software.
Discuss the reporting unit: QIDs internally, CVEs for external audiences, and governance over customer-severity overrides that change every dashboard.
## What a QID is Qualys VMDR (Vulnerability Management, Detection and Response) does not count findings in CVEs. It counts them in **QIDs**: Qualys IDs, unique numbers assigned to each detection in the **Qualys KnowledgeBase**. The VMDR onboarding guide says Qualys maintains more than 100,000 QIDs, kept up to date by its Threat Research team. Every row in the Vulnerabilities tab is a QID found on an asset, and every query, report and widget groups on that number. A QID bundles three things: - **A test.** How the scanner appliance or Cloud Agent decides the condition is present. The vulnerability details page calls this the detection logic. - **A description.** Title, category, the CVEs it relates to, the vendor references and the solution. - **Scoring metadata.** A Qualys severity from 1 to 5, and the inputs to the Qualys Detection Score (QDS). You can search for it directly in the Qualys Query Language (QQL): ``` vulnerabilities.vulnerability.qid: 90405 ``` ## Why a QID is not a CVE A CVE identifies a published flaw. A QID identifies Qualys's way of detecting something on a host. The two are related, but they do not map one to one. | | CVE | QID | |---|---|---| | Who assigns it | A CVE numbering authority | Qualys | | What it names | A disclosed flaw | A detection: a test and its result | | CVEs per item | One | Zero, one or several (`cveIds`) | | Can you author one | No | Yes, as a custom QID | Three consequences matter when you report on QIDs: 1. **One QID can carry several CVEs.** When it does, the QDS calculation uses the CVE with the highest score. If you count CVEs instead of QIDs, the numbers will not match VMDR's. 2. **Some QIDs carry no CVE.** Information-gathered QIDs record facts about a host. QID 45141 lists installed packages on Unix and Linux. QID 90235 lists applications enumerated from Windows Installer. The Vulnerability Predictions feature needs both to have run in an authenticated scan at least once. An option profile with "Complete" vulnerability detection includes them; a custom profile has to add them. 3. **You can write your own.** A **custom QID** is defined with Custom Assessment and Remediation (CAR) scripts, written in languages such as PowerShell or Python, which detect issues in first-party or open-source software. Custom QIDs live in the KnowledgeBase under the Custom QID category. They need a subscription enabled for Vulnerability Management Scan Processing (VMSP) and CAR 1.8.0.0 or later. ## Detection type, severity and score Each finding carries a **detection type**, searchable as `vulnerabilities.typeDetected`: - **Confirmed**: the test proved the condition. - **Potential**: the evidence points to the condition, but the test could not confirm it. - **Information**: an information-gathered fact, not a weakness. The VMDR Prioritization report includes only confirmed vulnerabilities. The `vulnerabilities.vulnerability.risk` token is ten times the severity for confirmed and potential findings, and equals the severity for information-gathered ones. Two severity values exist side by side. The **Qualys severity** (1 to 5, `vulnerabilities.vulnerability.severity`) is the KnowledgeBase value. The **customer severity** (`vulnerabilities.severity`) is one your subscription can set. If you never set it, it equals the Qualys value. The severity bar shows an arrow when you have raised or lowered a QID. Grouping by vulnerability lists the QID at your updated level, while vulnerability counts show it after the next asset scan. Separately, each detection gets a **QDS** from 1 to 100, which feeds the asset's TruRisk Score. ## Reading one QID's page From the QID column of the Vulnerabilities tab, open a QID to see two panels: - **Detection Summary**: the asset details and tags, the vulnerability result returned on that host, the description and the detection logic. The result is the evidence to read before anyone disputes a finding. - **QDS Details**: the contributing factors behind the score, namely the highest-contributing CVE, associated malware and threat actors, and when exploitability last trended. Reading the result field first often settles an "is this real?" question without re-running a scan. ## How to talk about it in an interview - Report on QIDs, and translate them to CVEs only for an external audience. - Read the detection type before you escalate. A Potential finding needs verification before it is treated as proven. - Treat a customer-severity change as a governed decision. It changes what your subscription's dashboards and counts show, not the KnowledgeBase entry other customers see.
- A stakeholder's spreadsheet counts 40 CVEs where VMDR shows 25 QIDs on the same host. Is one of them wrong?Not necessarily. A QID can list several CVEs in `cveIds`, so 25 QIDs can easily cover 40 CVEs. Information-gathered and custom QIDs carry no CVE at all. Reconcile by exporting the QIDs with their CVE lists. VMDR's Vulnerabilities tab can download data based on CVE or QID. Then report in the unit the audience needs.
- When would you write a custom QID rather than wait for Qualys to publish one?Write one for your own software or a niche component that Qualys's KnowledgeBase will never cover: an in-house agent, or a vulnerable internal library version. A custom QID uses CAR detection scripts, so the finding lands in the same inventory, prioritization and reporting as vendor QIDs. It needs VMSP enabled and CAR 1.8.0.0 or later, and you own its accuracy.
saying these in an interview costs you the question
- A QID is just Qualys's number for a CVE, one to one
- Every QID describes a vulnerability that needs patching
- Changing a QID's severity edits the shared KnowledgeBase entry
- Potential findings are proven flaws, just like Confirmed ones
- Counting CVEs gives the same total as counting QIDs