Tenable Research Release Highlights

Forum Discussion

Harry_NINT's avatar
Harry_NINT
Product Team
2 years ago

ESXi Version Information from vCenter REST API Summary We...

ESXi Version Information from vCenter REST API

Summary

We are proud to announce to our Tenable customers our latest integration enhancement with the ability to gather ESXi host version information from the vCenter REST API. This feature is available when using the VMware vCenter integration credential and the customer's vCenter/ESXi version is 7.0.3 or higher. 

This feature was developed for customers with ESXi hosts that are managed by a vCenter, but are not routable by the Nessus scanner on their network. Customer’s vCenter/ESXi environments may be configured as such where the ESXi hosts are not routable by the scanner for various reasons (ex. do not allow incoming connections, firewall rules, etc…). We now have the capability to get ESXi version information directly from the vCenter host REST API.

Credential Configuration Considerations 

Customers will not see any changes to the VMware vCenter credential. However, customers will need to enable Auto-Discovery of ESXi hosts to take advantage of this feature. When the ESXi host is automatically added to the scan using Auto-Discovery of ESXi hosts, Tenable determines if the scanner can communicate with the host. If not, Tenable will allow the host to be scanned and therefore vulnerability detections will run, at the very least based on the ESXi version information collected.

Release Date

March 25, 2024 - TVM, Nessus, and Security Center

2 Replies

  • christopher_bug's avatar
    christopher_bug
    Connect Contributor

    With this functionality are new hosts automatically added as assets in Tenable irrespective of if they can be reached, or, not? And likewise is there the ability for Tenable to automatically remove assets when they are removed from vCenter?

    • Harry_NINT's avatar
      Harry_NINT
      Product Team

      Hello Chris,

      Thank you for your questions. Yes, they will be added, but this only applies to vCenter-managed ESXi hosts when using auto-discovery. As for the ability to remove auto-discovered assets, we don’t currently have that capability but they can be manually removed. Once they are removed from vCenter they will not be auto-discovered.