Security and CVE registry
How to read the security overview, triage CVEs and set default AV/firewall policies.
Security overview
Section titled “Security overview”RMM → Security shows priorities: what is critical on the fleet and where to jump into devices. Start your morning risk review here.
- Open RMM → Security → Overview.
- Note critical / high items and device counts.
- Drill into a device or the CVE registry to plan remediation.
- Prioritize critical CVEs on servers and PCs holding customer data.
- After patching, refresh the scan — items should leave the backlog.
Triage the CVE registry
Section titled “Triage the CVE registry”Filter the CVE registry by severity (critical/high). Decide per application on a device (To fix tab): is a patch available, who owns the ticket. Impacts is for per-CVE detail.
A ticket from CVE is internal IT work (Service Desk queue, Internal badge). It does not appear in the customer portal (/user/tickets) as a report — including on a company account. The queue title is CVE-… — security vulnerability; the English NVD sentence stays underneath.
- Security → CVE registry → To fix (default).
- Update / ticket / accept on an app row, or multi-select for bulk app updates.
- Open Impacts for per-CVE triage, or use the device card → Apps.
- After patches, refresh the scan / close the related ticket.
- One app row covers all open CVEs for that app (one winget upgrade).
- The Impacts list shows CVE, CVSS, host and app — not the full NVD product catalog (that stays on the CVE database tab).
- Not every CVE needs same-day panic — weigh exposure and patch availability.
- Repeatable patching → Automation + maintenance window; exceptions → manual ticket.
Company security policy
Section titled “Company security policy”Tenant settings include default AV / firewall / Defender policies for the company. A device may override — check company policy first, then per-device exceptions.
- Sensible defaults mean less manual work on each new agent.
- Document exceptions (why disabled) — you will need them in an audit.
- Roles for these settings: see Roles, users and access.
GravityZone on the Protection tab
Section titled “GravityZone on the Protection tab”Device workbench → Protection shows Bitdefender quarantine separately from EDR incidents. Bitdefender Malware Status is not the same list. The hub does not alert on every isolated file — it warns only when remove or restore is pending or failed. cmd.exe without encryption is not a row on the events list (detections = Bitdefender). On Starter turn protection on in Settings → Company — RMM tries to create a separate GravityZone customer. Details: RMM — devices.