Skip to main content

CVE Module (Concept and Principles)

Medulla has added a new feature that allows the inventory database to be compared with CVE search APIs based on three CVE database models: NVD (U.S.), CIRCL (Luxembourg), and EUVD (European Agency).

This real-time comparison of the inventory database with these three CVE databases makes it possible to detect all CVE-related anomalies and provides system administrators and security teams with visibility into vulnerabilities on workstations associated with applications that are out of date or need to be updated across the entire fleet.

This module allows you to perform the following actions: 

  • View and launch a vulnerability scan across the entire fleet of managed machines in the Medulla interface
  • View and launch a vulnerability scan by entity. 
  • View and launch a vulnerability scan by group.
  • View the results of all CVEs across the fleet.

For each CVE reported in the module, they are ranked according to the severity priority of the vulnerability:

  • Low priority
  • Medium priority
  • High priority
  • Critical priority

A banner at the top of the module page provides a summary and an Overview of the status of security vulnerabilities across the system.

This banner displays: 

  • The total number of CVEs across the infrastructure.
  • The number of critical CVEs
  • The number of high-severity CVEs
  • The number of medium-severity CVEs
  • The number of low-severity CVEs
  • The number of affected machines.

image.png

To access this module, click the "Security" button:

image.png