Compliance Node Overview
MITRE CAPEC-310 (Scanning for Vulnerable Software) is a reconnaissance attack pattern in which an adversary engages in scanning activity to find vulnerable software versions or types (operating systems, network services). Typically follows port scanning. Severity: Low (recon phase - precedes exploitation). Maps to CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Parent: CAPEC-541 Application Fingerprinting. Compliance: NIST SP 800-53 CM-6/SC-7/RA-5, ISO 27001 A.8.8/A.8.16, PCI DSS v4.0 Req 11.3.1, NIS2 Article 21(2)(d).
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/310.html
SHA-256 integrity: 44943f0ae78b683501aedc1a4ccee92aa0a289af0d80c3dd190016252cac9519
Primary Citations — 8 traced to source
- MITRE CAPEC-310: Scanning for Vulnerable Software (https://capec.mitre.org/data/definitions/310.html)
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.