Mitigating Vulnerable CVEs
You can mitigate vulnerable CVEs by either isolating or applying the patch.
Isolating a Device
You can isolate a device from the network until you patch its vulnerable CVEs.
-
Go to .
-
To isolate specific devices.
-
From the View list, select Devices.
-
Select the devices and click .
-
-
To isolate all the devices affected by the CVE.
-
From the View list, select Vulnerabilities.
-
Click the vulnerability.
-
Select the devices and click .
Endpoint Security initiates the Isolate Device push operation. For more information, see Push Operations.
-
Applying the Patch for CVEs
-
Make sure that the Enable patch updates & reboot enforcement checkbox is selected for the policy. Otherwise, the patch is not applied to the endpoint.
-
A single patch can fix multiple CVEs.
-
Go to Asset Management > Posture Management.
-
To apply patches for specific vulnerabilities:
-
From the View list, select Vulnerabilities.
-
Select the CVEs and click
.
The Patch Details window appears.
-
Click Update Patch.
-
-
To apply the patches for specific device:
-
From the View list, select Devices.
-
Select and click the specific Device Name.
The Device Details window appears.
-
Select the CVEs and click
.
The Patch Details window appears.
-
Click Update Patch.
-
Verifying the Applied Patch
-
Scan the device to verify that all CVEs are patched.
-
If all the CVEs are patched and if the device is isolated (To verify, go to Asset Management > Organization > Computers.
From the View list, select Host Isolation, and then view the Isolation Status column) from the network, then add the device back to network. To add:
-
Go to Asset Management > Posture Management.
-
From the View list, select Devices.
-
Select the devices and click Push Operations > Release Device.
-
-
If required, reboot the device. To reboot:
-
Go to Asset Management > Posture Management.
-
From the View list, select Devices.
-
Select the devices and click Push Operations > Reboot Device.
-