Details Widget
Device Details Widget
To view the Device Details widget, in the Vulnerability Assessment Table, under the Device Name column, click a device name.
The Device Details widget shows:
-
Operating System name.
-
Operating System version.
-
Date and time the device was last scanned.
-
Number of vulnerabilities detected in the device.
-
Number of applications at risk.
-
Comment
CVE Details Widget
To view the CVE Details widget, in the Vulnerability Assessment Table, under the Vulnerabilities view, click a CVE number.
-
CVSS score of the device.
-
The application with the CVE.
-
The version of the application with the CVE.
-
Date and time the CVE was last detected.
-
Date and time the CVE was first detected.
-
Patch name available for update.
-
Size of the patch available for update.
-
Comment
Scanning Devices
You can scan devices for vulnerable CVEs or to verify if the patch has been applied or not.
To start the scan for the first time:
-
Go to Asset Management > Computers.
-
Select the devices for which you want to scan.
-
Right-click and select Vulnerabilities > Scan Now.
You can start subsequent manual scans by clicking Scan Now in Asset Management > Posture Management or by using the Run Diagnostics push operation.
To scan the devices:
- Go to Asset Management > Posture Management.
- To scan specific devices:
-
From the View list, select Devices.
-
Select the devices and click
.
-
- To scan all the devices affected by the CVE:
-
From the View list, select Vulnerabilities.
-
Select the CVE and click
.
-
Mitigating Vulnerable CVEs
You can mitigate vulnerable CVEs by either isolating or applying the patch.
Isolating a Device
You can isolate a device from the network until you patch its vulnerable CVEs.
- Go to Asset Management > Posture Management.
- To isolate specific devices:
- From the View list, select Devices.
- Select the devices and click Push Operation > Isolate Device.
- To isolate all the devices affected by the CVE:
- From the View list, select Vulnerabilities.
- Click the vulnerability.
- Select the devices and click Push Operation > Isolate Device.
Endpoint Security initiates the Isolate Device push operation. For more information, see Push Operations.
Applying the Patch for CVEs
-
Make sure that the Enable patch updates & reboot enforcement checkbox is selected for the policy. Otherwise, the patch is not applied to the endpoint. For more information, see Configuring Posture Assessment Settings.
-
A single patch can fix multiple CVEs.
- Go to Asset Management > Posture Management.
- To apply patches for specific vulnerabilities.
- From the View list, select Vulnerabilities.
- Select the CVEs and click
.
The Patch Details window appears.
- Click Update Patch.
- To apply the patches for specific device.
- From the View list, select Devices.
- Select and click the specific Device Name.
The Device Details window appears.
- Select the CVEs and click
.
The Patch Details window appears.
- Click Update Patch.
Verifying the Applied Patch
Make sure that the vendor sites are accessible for the endpoints to download the patches directly.
- Scan the device to verify that all CVEs are patched.
- If all the CVEs are patched and if the device is isolated (To verify, go to Asset Management
> Organization
>Computers, from the View list, select Host Isolation, and then view the Isolation Status column) from the network, then add the device back to network. To add:
- Go to Asset Management > Posture Management.
- From the View list, select Devices.
- Select the devices and click Push Operations > Release Device.
- If required, reboot the device. To reboot:
- Go to Asset Management > Posture Management.
- From the View list, select Devices.
- Select the devices and click Push Operations > Reboot Device.