Installed version appears old, distro backport is patched
The upstream version string remains vulnerable-looking, but the distro advisory says the fix was backported. Good evidence includes distro package release, advisory reference, host package output, and scanner plugin context.
Product family matches, component is not installed
A scanner or CPE match hits the product family, but the vulnerable optional feature is absent. Good evidence includes installed component list, configuration proof, service owner confirmation, and review trigger.
Fixed version exists, but upgrade path changes major version
The vendor fix requires a major upgrade or appliance firmware path. Good evidence includes supported upgrade path, rollback plan, vendor support statement, and temporary control decision.
Cloud provider fixed the managed service
The customer may not patch the platform, but still needs tenant validation. Good evidence includes provider advisory, tenant configuration state, customer-owned integrations, and monitoring responsibility.
Scanner plugin changed after advisory update
A new plugin detects a broader range than the earlier advisory. Good evidence includes plugin version, advisory revision date, affected range text, and a retest after owner validation.
Container base image patched, running workload is stale
The repository shows a fixed base image, but running workloads still use old layers. Good evidence includes image digest, deployment timestamp, running pod/task version, and redeploy proof.