OS Vulnerabilities

  1. Go to Policy and select a policy profile.
  2. Click Device > OS Vulnerabilities and set the Risk Level for these classifications.
    Classification Description Risk Level Condition
    iOS OS Version Select a Risk Level if the iOS version is older than the one specified in the Condition.
    • No Risk (Default)
    • High (Device Alert)
    • Medium (Device Alert)
    • Medium (No Device Alert)
    • Medium (Dismissive Device Alert)
    • Low
    • No Risk
    Specify the condition for the iOS version.
    Android OS Version Select a Risk Level if the Android OS version is older than the one specified in the Condition.
    • High (Device Alert)
    • Medium (Device Alert)
    • Medium (No Device Alert)
    • Medium (Dismissive Device Alert)
    • Low
    • No Risk
    Specify the condition for the Android OS version.
    New Security Patch Available

    Select a Risk Level if a new security patch update is available for the Android device but it is not installed for the duration specified in the Condition, after its release.

    Note:

    The availability of the patches depends on each Original Equipment Manufacturer (OEM). See https://source.android.com/docs/security/bulletin

    • No Risk (Default)
    • High (Device Alert)
    • Medium (Device Alert)
    • Medium (No Device Alert)
    • Medium (Dismissive Device Alert)
    • Low
    • No Risk
    Specify the duration. Default is one week.
    Security Patch Not Updated Select a Risk Level if the manufacturer has discontinued security patch updates or no security patch information available for the Android device since the duration specified in the Condition.
    • No Risk (Default)
    • High (Device Alert)
    • Medium (Device Alert)
    • Medium (No Device Alert)
    • Medium (Dismissive Device Alert)
    • Low
    • No Risk
    Specify the duration.
    CVEs detected on device OS

    Set a Risk Level for the highest Common Vulnerability Scoring System (CVSS) V3 score of the CVEs detected on the device OS version, as specified in the Condition.

    Note:

    CVSS is a severity score of the vulnerability from 0.1 (lowest) to 10.0 (highest). Check the CVEs scores at: https://nvd.nist.gov/Vulnerability-Metrics/.

    For full visibility of the CVEs detected across your mobile device fleet, go to Forensics > OS CVE Assessment.

    • High
    • Medium
    • Low
    • No Risk
    Specify the condition. For example, if the CVSS V3 score is above a certain range.
  3. To add CVEs that trigger a specific risk level on the user device, in the OS Vulnerabilities section, click Add.
  4. Enter the CVE and the Risk Level.
  5. To save the policy changes, click Save.