Details Widget

Device Details Widget

To view the Device Details widget, in the Vulnerability Assessment Table, under the Device Name column, click a device name.

The Device Details widget shows:

  • Operating System name.

  • Operating System version.

  • Date and time the device was last scanned.

  • Number of vulnerabilities detected in the device.

  • Number of applications at risk.

  • Comment

CVE Details Widget

To view the CVE Details widget, in the Vulnerability Assessment Table, under the Vulnerabilities view, click a CVE number.

  • CVSS score of the device.

  • The application with the CVE.

  • The version of the application with the CVE.

  • Date and time the CVE was last detected.

  • Date and time the CVE was first detected.

  • Patch name available for update.

  • Size of the patch available for update.

  • Comment

Scanning Devices

You can scan devices for vulnerable CVEs or to verify if the patch has been applied or not.

Note:

To start the scan for the first time:

  1. Go to Asset Management > Computers.

  2. Select the devices for which you want to scan.

  3. Right-click and select Vulnerabilities > Scan Now.

You can start subsequent manual scans by clicking Scan Now in Asset Management > Posture Management or by using the Run Diagnostics push operation.

To scan the devices:

  1. Go to Asset Management > Posture Management.
  2. To scan specific devices:
    1. From the View list, select Devices.

    2. Select the devices and click .

  3. To scan all the devices affected by the CVE:
    1. From the View list, select Vulnerabilities.

    2. Select the CVE and click .

Mitigating Vulnerable CVEs

You can mitigate vulnerable CVEs by either isolating or applying the patch.

Isolating a Device

You can isolate a device from the network until you patch its vulnerable CVEs.

  1. Go to Asset Management > Posture Management.
  2. To isolate specific devices:
    1. From the View list, select Devices.
    2. Select the devices and click Push Operation > Isolate Device.
  3. To isolate all the devices affected by the CVE:
    1. From the View list, select Vulnerabilities.
    2. Click the vulnerability.
    3. Select the devices and click Push Operation > Isolate Device.

    Endpoint Security initiates the Isolate Device push operation. For more information, see Push Operations.

Applying the Patch for CVEs

Note:
  • Make sure that the Enable patch updates & reboot enforcement checkbox is selected for the policy. Otherwise, the patch is not applied to the endpoint. For more information, see Configuring Posture Assessment Settings.

  • A single patch can fix multiple CVEs.

  1. Go to Asset Management > Posture Management.
  2. To apply patches for specific vulnerabilities.
    1. From the View list, select Vulnerabilities.
    2. Select the CVEs and click .

      The Patch Details window appears.

    3. Click Update Patch.
  3. To apply the patches for specific device.
    1. From the View list, select Devices.
    2. Select and click the specific Device Name.

      The Device Details window appears.

    3. Select the CVEs and click .

      The Patch Details window appears.

    4. Click Update Patch.

Verifying the Applied Patch

Make sure that the vendor sites are accessible for the endpoints to download the patches directly.

  1. Scan the device to verify that all CVEs are patched.
  2. If all the CVEs are patched and if the device is isolated (To verify, go to Asset Management > Organization >Computers, from the View list, select Host Isolation, and then view the Isolation Status column) from the network, then add the device back to network. To add:
    1. Go to Asset Management > Posture Management.
    2. From the View list, select Devices.
    3. Select the devices and click Push Operations > Release Device.
  3. If required, reboot the device. To reboot:
    1. Go to Asset Management > Posture Management.
    2. From the View list, select Devices.
    3. Select the devices and click Push Operations > Reboot Device.