User guideVulnerabilities

Understand vulnerabilities

RemediForge compares what each host has installed with published vulnerability information from the operating system and software vendors and from security agencies. Every host is checked again every 12 hours.

See them for one host on its Vulnerabilities tab, or for the whole estate on Vulnerabilities.

Why more vulnerabilities than updates?

A vulnerability is one CVE in one package. An update is one package. One update usually closes several CVEs (a single curl or Python update can close ten), so a host with 22 updates can have 60 vulnerabilities. Patching the updates removes most of them at once.

Labels

Label Means
Fix available An update that fixes it is offered to this host now: patch it
Not offered yet A fixed version exists, but the host's package source does not offer it yet; it turns into an update when it does
Restart to apply The fix is installed but the host has not restarted (a kernel, for example)
Exploited Attackers are using it now: patch these first
Third-party Software that does not come from the operating system's vendor

By default the lists show what you can act on. Fix available narrows to findings with an update now, and Exploited only to the urgent ones.

Libraries inside applications

Applications on a host often carry their own libraries: npm packages in a Node.js app, Python packages, Java JAR files, Go modules. RemediForge finds them in the usual application folders and checks each exact version for known vulnerabilities.

These findings are labelled Application library, and Found in shows the folders. On Vulnerabilities, set Source to Application libraries to see only these.

RemediForge does not update them: a system update cannot change a library an application ships with. Pass the finding to the application's owner, who updates the library and releases the application again. The finding goes away at the host's next inventory after that.

Third-party software coverage

The Third-party software panel says, for instance, "2 of 9 third-party packages have CVE coverage". It means RemediForge found the other seven programs installed but the public vulnerability data has no entry it can match them to, so it cannot judge them either way. Browser shortcuts (web apps such as Gmail or Docs) and hardware drivers are typical. It is not a finding; it tells you where RemediForge cannot see.

Risk score

Each host also gets a risk score from its findings, how critical the host is (set its business context under Asset details), whether it faces the internet, and how likely its vulnerabilities are to be exploited.

Understand vulnerabilities | RemediForge