Vulnerability Management

Last Updated At: 2025-10-17 11:06:39

Vulnerability management aims to help customers scan security vulnerabilities in the system and provide vulnerability information, repair suggestions, etc. Some vulnerabilities can enable precise defense and can be automatically repaired. This document guides you on how to perform vulnerability management.

Restriction Description

  • Vulnerability management range description: the following

    Vulnerability Management FeatureVulnerability TypeLinux SystemWindows Systems
    Vulnerability Scanning
    Pro edition, flagship edition host applicable
    Linux Software Vulnerabilities×
    Windows System Vulnerabilities×
    Web-CMS Vulnerabilities
    Application Vulnerabilities
    Vulnerability Defense
    Flagship edition host applicable
    Linux Software Vulnerabilities××
    Windows System Vulnerabilities××
    Web-CMS VulnerabilitiesOnly support some vulnerabilities.×
    Application Vulnerabilities✓Only some vulnerabilities are supported.×
    Automatic Vulnerability Repair
    Flagship edition host applicable
    Linux Software Vulnerabilities✓ Only some vulnerabilities are supported.×
    Windows System Vulnerabilities××
    Web-CMS Vulnerabilities✓ Only some vulnerabilities are supported.✓ Only some vulnerabilities are supported.
    Application Vulnerabilities××
  • Since vulnerability repair may disrupt user business, automatic vulnerability repair is not performed immediately after vulnerability detection. Users must understand the vulnerability, click Repair, and back up data before automated repair can be performed.

Vulnerability Scanning

  1. Log in to the tenant-side console of Cloud Workload Protection Platform, and click Vulnerability Management in the left sidebar.
  2. In the vulnerability scanning module, support one-click scan, scheduled scan settings.
    • Click One-Click Scan , and the one-click scan settings popup will open. You can configure the vulnerability type, vulnerability level, scan timeout duration, and scan server range for this scan.
    • Click Scan Setting to open the vulnerability settings pop-up and anchor to Scheduled Scan. You can configure the scheduled scan switch, period, vulnerability level, and vulnerability type.
    • Click Details to view the details of the last scan. PDF scan reports and Excel scan results are supported for download.

Vulnerability Defense

In the Vulnerability Defense module, you can enable/disable the vulnerability defense switch, view the number of protected hosts, the successful prevention count, and defense trends.

  • Click Defense Setting to open the vulnerability settings pop-up and anchor to Vulnerability Defense. You can set the vulnerability defense switch, view protectable vulnerabilities, select the protection host range, and view the defense plugin details.
  • Click Successful Prevention Count, and you can view the attacks that have been successfully defended against currently and view attack details.

Vulnerability Handling

  1. Below the vulnerability management page, you can view the statistical data and detailed vulnerability list of the currently detected vulnerabilities.
  2. In the [Vulnerability Overview] module, the vulnerability detection status, frequency of network attack events, and today's additions are displayed, as well as the total count of the host security vulnerability database. Field Descriptions:
    • The total number of all vulnerabilities: the number of detected Linux software vulnerabilities, Windows system vulnerabilities, Web-CMS vulnerabilities, and application vulnerabilities.
    • Number of affected hosts: the number of hosts where vulnerabilities are detected.
    • Network attack events: statistics of the number of network attack events within the last month.
    • Supported vulnerabilities: You can view the vulnerability database supported by CWPP for detection. You can perform up to 20 retrievals each day. A single search can show up to 100 results.
  3. In the Vulnerability List module, show the current detected specific vulnerabilities, which are divided into two categories: Urgent Vulnerability and All Vulnerabilities. The functionality of the two is not very different. Below, take All Vulnerabilities as an example to introduce vulnerability handling. Field Descriptions:
    • Vulnerability name/tag: The vulnerability name refers to the currently detected vulnerability, and the tag refers to the tag of the vulnerability (such as RemoteExploit, service restart, exist EXP, etc.).
    • Vulnerability type: Linux software vulnerability, Windows system vulnerability, Web-CMS vulnerability, application vulnerability.
    • Threat level: critical, high risk, medium risk, low risk.
    • CVSS: Refers to the score of the common vulnerability scoring system. The score range is from 0 to 10. 0 represents the least severe, and 10 represents the most severe.
    • CVE No.: The unique number to identify the security vulnerability in the public vulnerability exposure database.
    • Last scan time: the time when this vulnerability was last detected.
    • Number of affected hosts: the number of hosts with this vulnerability.
    • Processing status: to be fixed, in remediation, scan in progress, fixed, ignored.
    • Defense status: defending.
    • Perform an operation
      • Repair plan: For vulnerabilities that cannot be fixed automatically, click Repair Plan to open the vulnerability details pop-up and manually fix vulnerabilities according to the repair plan.
      • Automatic fix: Some Linux software vulnerabilities and Web-CMS vulnerabilities support automatic fix. Click Automatic Fix to open the vulnerability details pop-up, select the servers that need to be repaired, and proceed with the necessary fixes.
      • More: Rescan (rescan this vulnerability); Ignore (ignore this vulnerability and do not scan the host for this vulnerability in the future).