CVE Search
You can search for a particular CVE The Common Vulnerabilities and Exposures (CVE) system provides a reference-method for publicly known information-security vulnerabilities and exposures. found in your scanned assets regardless of policies configured for your environment. The CVE Search page shows all the CVEs found in your onboarded environments.
Use Case
CVE Search allows you to find all workload assets affected by a CVE. The search results show all the occurrences of the searched CVE ID in the affected assets, with one result for each occurrence.
|
Note - If an asset has multiple occurrences of the searched CVE ID, the search results show each of the occurrences. |
How it Works
CloudGuard scanners (AWP and Image Assurance) find the CVEs when scanning your environments and assets, for example, images or Virtual Machine instances.
Supported assets:
-
Azure Collection of integrated cloud services that developers and IT professionals use to build, deploy, and manage applications through a global network of data centers managed by Microsoft®. Virtual Machines, FunctionApps
-
AWS Amazon® Web Services. Public cloud platform that offers global compute, storage, database, application and other cloud services. EC2 Amazon EC2 - A web service for launching and managing Linux/UNIX and Windows Server instances in Amazon data centers. instances
-
Kubernetes Kubernetes, often abbreviated as “K8s”, orchestrates containerized applications to run on a cluster of hosts. images, workloads
-
Container Registry A collection of repositories used to store and access container images. images
Searching
To search for a CVE:
-
Navigate to Workload Protection > Vulnerabilities > CVE Search.
-
Enter the CVE ID in the search bar and click Search. CloudGuard shows all assets affected by the CVE and their information:
-
Affected asset (for example, a workload that runs the affected image), its type, name, and link to the page
-
Scanned asset (for example, an image scanned by the CloudGuard scanner), its type, and name
-
Package name and version
-
Environment where the vulnerability is found
-
Remediation for the vulnerability
-
-
To limit the search results by certain criteria, use the filter. For example, you can show only fixable vulnerabilities or only in a particular environment.
-
Click the CVE ID to see its details. CloudGuard shows this information in a sliding panel:
-
CVE severity (color and symbol)
-
Source
-
Description
-
Remediation (if applicable) - Remediation is the package version that you need to upgrade to.
-
Affected asset details
-
Containing package
-
To export the search results:
-
Navigate to Workload Protection > Vulnerabilities > CVE Search.
-
Enter the CVE ID in the search bar and click Search. CloudGuard shows all assets affected by the CVE.
-
On the top bar, click Export and select:
-
Export to see basic CVE information
-
Export Extended to see full CVE information
CloudGuard shows the results in CSV format.
-
Known Limitations
The exported results do not include the Scan Source parameter.