Chapter 15: CVE

CVE Module (Concept and Principles)

Medulla has introduced a new feature that allows the inventory database to be compared with CVE search APIs based on three CVE database models: NVD (U.S.), CIRCL (Luxembourg), and EUVD (European Union).

This real-time comparison of the inventory database with these three databases enables the detection of all CVE-related anomalies and provides system administrators and security teams with visibility into vulnerabilities on workstations linked to applications that are out of date or need to be updated across the network.

This module allows you to perform the following actions: 

For each CVE reported in the module, we organize a ranking based on the severity priority of the vulnerability:

A banner at the top of the module page provides a summary and an overview of the status of security vulnerabilities across the fleet.

This banner displays: 

image.png

To access this module, click the security button:

image.png



CVE operation

When you access the CVE module, it provides an overview of the CVEs across the infrastructure, their severity, and the number of affected machines.

By clicking on the CVE summary banner, you can create groups based on severity. You can also click the trash can button to exclude CVEs, machines, or groups from the CVE lists.

You can view the details of each CVE by using the CVE search APIs to retrieve information about the vulnerability and its impact.

You can sort this by entity, search for a specific CVE, or run a scan.

image.png

On the left-hand menu, you will find the different views: 

Results view by machine

Result view by machine: 

image.png

In this view, you will see all machines affected by CVEs:

image.png

By clicking the button to view details, you’ll see the CVEs listed by application. You can drill down further by selecting a specific CVE—for example, Flatpak—if you want to see more information about that vulnerability. Just click the button in the actions menu. 

image.png

In this view, you’ll find the following information: 

Clicking the action button for CVE-2024-42472 will give me a complete view of the CVE taken directly from the CVE database

image.png

Results view by entity

Results view by entity:

image.png

This view displays only the entity-based view and includes the following information: 

By clicking the "Details by Entity" button: You will see the details view by machine, showing only the machines in that entity.

image.png

Results view by group

Results View by Group

image.png

This view displays only the machine group view and includes the following information:

By clicking the "Details by Group" button, you can view the details by machine, showing only the machines in that group. 

image.png

View all CVEs

View all CVEs

image.png

Here you will find all CVEs and the following information:

When you click on "Details," you will see the CVE record that was displayed in the main view: 

image.png

CVE settings.

In the settings menu, you will be able to configure 

image.png

 

Display filters: 

You can select display filters based on the following options: 

Software Filters: 

We can apply filters to the software we want to exclude from the list of CVEs. : 

image.png

CVE filters:

We will apply filters to the CVEs we want to exclude from the list: 

image.png

Vendor filters:

We will apply filters to the vendors we want to exclude from the CVE list.

image.png

Machine filters: 

We will set exclusions for the machines we want to exclude. To do this, simply click on the image.pngin the list of machines.

 

image.png

Group filters:

We will set exclusions for groups. To do this, simply click the button in the list of groups image.png.

image.png