Forum Discussion
Vendor Unpatched Vulnerability Coverage Summary Tenable is...
Vendor Unpatched Vulnerability Coverage
Summary
Tenable is making fundamental improvements to reporting findings for vulnerabilities that do not have a patch available from the vendor (Vendor Unpatched Vulnerabilities). Customers can now scan for Red Hat Enterprise Linux, Ubuntu, and Debian Linux vulnerabilities that do not have a patch available.
Impact
Customers who opt-in to scanning for Vendor Unpatched Vulnerabilities by adding the “Scan for unpatched vulnerabilities (no patched or mitigations available)” setting to their scan policy will be able to scan for this class of vulnerability.
Tenable will publish a plugin for each CVE with a vulnerability without a patch in any affected and supported operating systems. At this time, Red Hat Enterprise Linux, Ubuntu, and Debian Linux are supported for this feature. Should one or more of the vendors release a patch for one or more of the affected packages, the relevant check(s) will be removed from the plugin; if no checks remain, the plugin will be deprecated. Since the information provided by the vendor does not include which versions of a given package are affected, the checks simply test for the presence of the affected package at any version.
The initial feature release will contain approximately 6,000 plugins. As these plugins are released, they will be reflected in the Plugin Search results page here. Due to the large number of plugins being released during this initial cycle, customers will experience a significant plugin feed differential.
Target Release Date
March 4, 2025