Skip to main content

CVE Dashboard

The CVE Dashboard in SureMDM offers a centralized interface for monitoring and managing vulnerabilities affecting Windows devices.

note

This feature is available exclusively in the Premium and Enterprise tiers and supports devices running Windows 10 and Windows 11.

  1. Log in to the SureMDM Web Console.
  2. Navigate to the Security tab.
  3. Click on CVE Dashboard from the left-hand menu.

Dashboard Overview

The CVE Dashboard provides insights through two primary charts:

1. CVE Status Chart

This chart displays the total number of devices affected by all CVEs. It categorizes devices into:

  • At Risk Devices: Devices that are currently vulnerable.
  • Resolved Devices: Devices where the vulnerabilities have been addressed.

This chart gives a clear overview of the current security status across all your devices.

2. Severity Chart

The Severity chart categorizes devices based on the severity levels of vulnerabilities. Severity levels include:

  • Critical: High-priority vulnerabilities requiring immediate attention.
  • Important: Significant vulnerabilities that could impact system security.
  • Moderate: Vulnerabilities with a lesser impact on security.
  • Low: Minor vulnerabilities with minimal risk.
  • None: Devices with vulnerabilities that have no severity (usually app-based CVEs).

Clicking on any section of this chart allows you to view detailed information about devices affected by vulnerabilities within that severity category.

Detailed CVE Table

The dashboard includes a comprehensive table with the following columns:

Column NameDescription
CVE NumberUnique identifier for the vulnerability (e.g., CVE-2024-43633).
CVE TitleBrief description of the vulnerability.
ProductTarget Windows version (e.g., Windows 11 Version 22H2).
ClassificationType of update (e.g., Security Update).
Published DateDate the vulnerability was reported.
KB NumberCorresponding Microsoft Knowledge Base number.
SeverityIndicates vulnerability severity (Important, Critical).
At Risk DevicesNumber of devices affected.
Safe DevicesNumber of devices where the issue is resolved.
Reboot RequiredIndicates if a device reboot is required post-update.
Base/Temporal ScoreCVSS scores representing vulnerability impact.
Issuing CNAOrganization that reported the vulnerability.

Resolve At-Risk Devices

The Resolve At-Risk Devices action allows administrators to quickly address vulnerabilities detected in devices by applying necessary patches and updates.

Steps to Resolve At-Risk Devices

  1. Navigate to the CVE Dashboard.
  2. In the CVE Table, identify CVEs with "At Risk Devices" listed.
  3. Click the Resolve At-Risk Devices button located above the CVE table.
  4. Select the CVEs from the table list.
  5. Click Resolve At-Risk Devices to resolve detected vulnerabilities.

Alternatively:

  1. Click on At-Risk Devices count and choose specific devices for a given CVE.
  2. Select the required device(s).
  3. Click Resolve At-Risk Devices to resolve detected vulnerabilities.
note
  • The Resolve At-Risk Devices action streamlines CVE management by directly addressing vulnerabilities for devices listed as "At Risk."
  • Device reboots may be required depending on the applied patches. Refer to the Reboot Required column in the CVE Table for details.

Additional Options on the Overview Page

  • Export: Exports the table data to be saved locally in CSV format.
  • Search Box: Allows users to search for specific information.
  • Refresh Icon: Updates the table with real-time data.
  • Column Chooser: Choose additional non-default columns.
note

The CVE Dashboard feature is available under the Security tab in SureMDM's Premium and Enterprise tiers. It currently scans and reports vulnerabilities for Windows 10 and 11, with reported dates after January 2023.