Skip to content
Open app
Open app

Security and CVE registry

How to read the security overview, triage CVEs and set default AV/firewall policies.

RMM → Security shows priorities: what is critical on the fleet and where to jump into devices. Start your morning risk review here.

  1. Open RMM → Security → Overview.
  2. Note critical / high items and device counts.
  3. Drill into a device or the CVE registry to plan remediation.
  • Prioritize critical CVEs on servers and PCs holding customer data.
  • After patching, refresh the scan — items should leave the backlog.

Filter the CVE registry by severity (critical/high). Decide per application on a device (To fix tab): is a patch available, who owns the ticket. Impacts is for per-CVE detail.

A ticket from CVE is internal IT work (Service Desk queue, Internal badge). It does not appear in the customer portal (/user/tickets) as a report — including on a company account. The queue title is CVE-… — security vulnerability; the English NVD sentence stays underneath.

  1. Security → CVE registry → To fix (default).
  2. Update / ticket / accept on an app row, or multi-select for bulk app updates.
  3. Open Impacts for per-CVE triage, or use the device card → Apps.
  4. After patches, refresh the scan / close the related ticket.
  • One app row covers all open CVEs for that app (one winget upgrade).
  • The Impacts list shows CVE, CVSS, host and app — not the full NVD product catalog (that stays on the CVE database tab).
  • Not every CVE needs same-day panic — weigh exposure and patch availability.
  • Repeatable patching → Automation + maintenance window; exceptions → manual ticket.

Tenant settings include default AV / firewall / Defender policies for the company. A device may override — check company policy first, then per-device exceptions.

  • Sensible defaults mean less manual work on each new agent.
  • Document exceptions (why disabled) — you will need them in an audit.
  • Roles for these settings: see Roles, users and access.

Device workbench → Protection shows Bitdefender quarantine separately from EDR incidents. Bitdefender Malware Status is not the same list. The hub does not alert on every isolated file — it warns only when remove or restore is pending or failed. cmd.exe without encryption is not a row on the events list (detections = Bitdefender). On Starter turn protection on in Settings → Company — RMM tries to create a separate GravityZone customer. Details: RMM — devices.