Enhanced Linux CVE Detection

Enhanced Linux CVE Detection

We are enhancing vulnerability detection for Linux endpoints to provide visibility into CVEs even when a corresponding security patch is not yet available.

What’s changing?

With this enhancement, Endpoint Central will detect unpatched Linux CVEs based on the vulnerable packages installed on managed endpoints, even when a patch has not yet been released for the CVE.

If an affected package and version are identified on an endpoint, the associated CVE will be detected and reported.

What to expect?

After this enhancement is rolled out, you may notice an increase in the number of vulnerabilities reported for Linux endpoints. This is expected, as the vulnerability count will now include CVEs for which a patch is not yet available, in addition to vulnerabilities that already have applicable patches.

This provides broader visibility into your Linux vulnerability exposure and helps you identify affected endpoints and take appropriate mitigation measures while waiting for the vendor to release a patch.

Once a patch becomes available, you can proceed with remediation through the applicable patch management workflow.

Regards,
The ManageEngine Team