---
title: "BOD 22-01 Cynergy Identified Vulnerabilities"
canonical: "https://kb.cynergy.app/space/MD/903806982/BOD%2022-01%20Cynergy%20Identified%20Vulnerabilities"
format: markdown
---
CISA is managing a catalog of known exploited vulnerabilities that carry significant risk to federal enterprises [https://cisa.gov/known-exploited-vulnerabilities](https://www.cisa.gov/known-exploited-vulnerabilities) and establishes requirements for agencies to remediate any such vulnerabilities included in the catalog. 

CISA determines vulnerabilities warranting inclusion in the catalog based on reliable evidence that the exploit is being actively used to exploit public or private organizations by a threat actor. This directive enhances but does not replace BOD 19-02, which addresses remediation requirements for critical and high vulnerabilities on internet-facing federal information systems.

**Cynergy enables addressing BOD 19-02 in the face of BOD 22-01. Cynergy has the ability to detect the internet-facing assets of the organization and identify the vulnerabilities to remediate based on the Known Exploited Vulnerabilities list. **

The vulnerabilities can be identified by the Cynergy Vulnerability Assessment and Automated Exploitation modules.

Currently, Cynergy allows identifying ~20% of all “Known Exploitable Vulnerabilities” based on BOD 22-01. 

The full list of CVEs and the ability of Cynergy to detect them can be found [here](https://kb.cynergy.app/space/MD/904069123/Known+Exploitable+Vulnerabilities+-+Identifiable+by+Cynergy).

![image](media://9e70083b-63b8-4f39-8e08-85458ea4d8f2)