Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable Blog

Subscribe

New Nessus Report Consolidates Missing Patches

Ensuring that patches are applied to systems is a complex problem. Pinpointing those patches that must be applied to become current requires careful analysis. The new Nessus consolidated “Patch Report” plugin identifies which patches to apply to protect your systems.

The Challenges of Patching

Regardless of platform, there are a plethora of patches to be applied. I tend to break them up into three general categories:

  1. Operating System (OS) Patches - These are patches made available by your OS vendor. In the case of Microsoft Windows and Apple OS X, it's fairly straight forward as patches are released that apply primarily to the software which comes with the OS. Microsoft also provides regular patch updates for Microsoft Office as well.
  2. 3rd-party Applications - Software installed by the user (outside of any package management system) is classified as third-party. Popular software, such as web browsers and related add-ons (Oracle Java, Adobe Flash), plague this category, making it challenging to manage and keep up-to-date.
  3. Packages Offered by the Distribution - In the case of Linux/UNIX, the OS patches are extended by the package management system and offer patches for your kernel, core software, and other software installed by the distribution. This software sits somewhere between the OS and third-party software.

Systems will often become out-of-date rather quickly, especially those that may have fallen outside your patch management strategy. When these hosts are scanned by Nessus, sometimes more than 100 different missing patches will be reported. For example, you can get a complete report of missing Microsoft patches for each host:

Nessus
The above unconsolidated list is generated for Windows hosts that were scanned and missing OS patches.

Consolidated OS Patches

Nessus now helps with patch consolidation. The new Nessus “Patch Report” plugin (ID #66334) will display a list of consolidated patches, only showing the patches that need to be applied and omitting superseded patches:

Nessus
Nessus will display the list of patches that are required to become fully patched.

The new plugin can also exclude superseded patches from the results. The following option allows the user to control this behavior:

Nessus policy preferences
By default, Nessus will not remove results from plugins that reported superseded patches. However, unchecking the preference setting above will remove superseded patch results.

Consolidated Third-party Application Patches

The "Patch Report" will also summarize patches for third-party software. For example, let's say that you've scanned a target that's running an outdated version of Adobe Flash. The missing patches are represented as follows:

Nessus
Using credentials, Nessus determined that there are several missing updates for Adobe Flash. Adobe regularly releases updates for Flash, making it difficult to determine which updates need to be installed to become current.

In order to keep this system up-to-date, not necessarily all of the patches listed above need be applied. It's more likely that applying one Adobe Flash update will install all of the missing updates. The Nessus "Patch Report" plugin now reports this information and presents a consolidated list of patches that must be applied:

Nessus
The patch report above provides instructions on which updates need to be installed, paring it down from several plugins to just one action.

Platform Support

The new "Patch Report" plugin supports all major platforms (Windows, OS X, UNIX, and Linux) and includes both OS and third-party software patches. Linux local patch checking is still in the works; however, if Nessus finds vulnerable software remotely (without credentials), a consolidated patch report is still issued. For example, Nessus found two vulnerabilities (and one informational level result) in the running Apache web server:

Nessus
Two vulnerabilities exist in the remote Apache server, each specifying a different version of the software be installed in order to remediate the vulnerability.

The solution for the "Apache Byte Range DoS" vulnerability is to upgrade to Apache version 2.2.21 or later. The solution for the "httpOnly Cookie Information Disclosure" vulnerability is to upgrade to 2.2.22 or later, resulting in the following patch report:

Nessus
By simply applying one update to Apache, both security vulnerabilities can be remediated.

Conclusion

Systems administrators are already overwhelmed with their daily tasks. When security assessments are performed, it can be perceived as added work to sift through vulnerabilities and figure out what needs to be done to remediate the issues. The new Nessus "Patch Report" plugin will foster better communication and teamwork between the security and systems administration groups, allowing Nessus to make an actionable report.

Resources

  • If a Security Control Falls in the Forest... - "Many guidelines and compliance standards state that in order to be "secure" or "compliant," all of your systems must be patched. Turns out that this is easier said than done. Just when you believe your systems to be patched, something fails and patches seemingly disappear."

Related Articles

Cybersecurity News You Can Use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Try Tenable Web App Scanning

Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable One Exposure Management platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. Sign up now.

Your Tenable Web App Scanning trial also includes Tenable Vulnerability Management and Tenable Lumin.

Buy Tenable Web App Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

5 FQDNs

$3,578

Buy Now

Try Tenable Lumin

Visualize and explore your exposure management, track risk reduction over time and benchmark against your peers with Tenable Lumin.

Your Tenable Lumin trial also includes Tenable Vulnerability Management and Tenable Web App Scanning.

Buy Tenable Lumin

Contact a Sales Representative to see how Tenable Lumin can help you gain insight across your entire organization and manage cyber risk.

Try Tenable Nessus Professional Free

FREE FOR 7 DAYS

Tenable Nessus is the most comprehensive vulnerability scanner on the market today.

NEW - Tenable Nessus Expert
Now Available

Nessus Expert adds even more features, including external attack surface scanning, and the ability to add domains and scan cloud infrastructure. Click here to Try Nessus Expert.

Fill out the form below to continue with a Nessus Pro Trial.

Buy Tenable Nessus Professional

Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Tenable Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.

Buy a multi-year license and save. Add Advanced Support for access to phone, community and chat support 24 hours a day, 365 days a year.

Select Your License

Buy a multi-year license and save.

Add Support and Training

Try Tenable Nessus Expert Free

FREE FOR 7 DAYS

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Already have Tenable Nessus Professional?
Upgrade to Nessus Expert free for 7 days.

Buy Tenable Nessus Expert

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Select Your License

Buy a multi-year license and save more.

Add Support and Training