Mitigating Vulnerable CVEs

You can mitigate vulnerable CVEs by either isolating or applying the patch.

Isolating a Device

You can isolate a device from the network until you patch its vulnerable CVEs.

  1. Go to Asset Management > Posture Management.

  2. To isolate specific devices.

    1. From the View list, select Devices.

    2. Select the devices and click Push Operation > Isolate Device.

  3. To isolate all the devices affected by the CVE.

    1. From the View list, select Vulnerabilities.

    2. Click the vulnerability.

    3. Select the devices and click Push Operation > Isolate Device.

    Endpoint Security initiates the Isolate Device push operation. For more information, see Push Operations.

Applying the Patch for CVEs

Note:
  • Make sure that the Enable patch updates & reboot enforcement checkbox is selected for the policy. Otherwise, the patch is not applied to the endpoint.

  • A single patch can fix multiple CVEs.

  1. Go to Asset Management > Posture Management.

  2. To apply patches for specific vulnerabilities:

    1. From the View list, select Vulnerabilities.

    2. Select the CVEs and click .

      The Patch Details window appears.

    3. Click Update Patch.

  3. To apply the patches for specific device:

    1. From the View list, select Devices.

    2. Select and click the specific Device Name.

      The Device Details window appears.

    3. Select the CVEs and click .

      The Patch Details window appears.

    4. Click Update Patch.

Verifying the Applied Patch

Note:
Make sure that the vendor sites are accessible for the endpoints to download the patches directly.
  1. Scan the device to verify that all CVEs are patched.

  2. If all the CVEs are patched and if the device is isolated (To verify, go to Asset Management > Organization > Computers.

    From the View list, select Host Isolation, and then view the Isolation Status column) from the network, then add the device back to network. To add:

    1. Go to Asset Management > Posture Management.

    2. From the View list, select Devices.

    3. Select the devices and click Push Operations > Release Device.

  3. If required, reboot the device. To reboot:

    1. Go to Asset Management > Posture Management.

    2. From the View list, select Devices.

    3. Select the devices and click Push Operations > Reboot Device.