Locating and downloading CVE Status lists for VCF
search cancel

Locating and downloading CVE Status lists for VCF

book

Article ID: 450429

calendar_today

Updated On:

Products

VMware Cloud Foundation

Issue/Introduction

Customers reviewing vulnerability scan results against VCF infrastructure need access to Broadcom's official Security Vulnerability (CVE) status list to determine whether a flagged CVE status has already been provided. This article explains where to locate and download the Security Vulnerability statuses.

Environment

VCF 9.x
VCF 5.2.x

Resolution

The CVE disposition list is published as a downloadable CSV file under the product entitlement for each supported VCF release. Navigate to the file as follows:

For VCF 9.1:

  1. Log in to the Broadcom Support Portal with an active VCF entitlement.
  2. Select My Downloads from the left hand panel
  3. Select VMware Cloud Foundation.
  4. Select VMware Cloud Foundation 9.
  5. Select version 9.1.0.0.
  6. Select Additional Downloads.
  7. Search for CVE
  8. Agree to the Terms and Conditions
  9. Locate and download the CVE disposition CSV.

For VCF 5.2.x (Legacy VMware Cloud Foundation Versions)

  1. Log in to the Broadcom Support Portal with an active VCF entitlement.
  2. Select My Downloads from the left hand panel
  3. Select VMware Cloud Foundation.
  4. Select Legacy VMware Cloud Foundation Versions.
  5. Select version 5.2.4.0 .
  6. Select Primary Downloads.
  7. Agree to the Terms & Conditions
  8. Locate and download the CVE disposition CSV.

Scope of Status Coverage

Broadcom's disposition review currently focuses on Critical and High severity CVEs. Medium and Low severity CVEs are frequently patched in our Major, Minor and Maintenance releases as part of regular VCF software component lifecycle management, while prioritizing product stability and quality. Support does not individually provide status for these vulnerabilities.   

Scanning Methodology Requirements

Status review and support engagement apply only to findings from scans run at standard/normal sensitivity which identify CVEs of either critical/high/medium:

  • Nessus: Report Paranoia setting of Normal / Avoid False Alarms.
  • Qualys: Detection category of Confirmed Vulnerability.

Note: This policy is applicable to all vulnerability scanners, which must adhere to the recommendations specified above.

Findings surfaced at elevated sensitivity settings (Nessus "Paranoid," Qualys " Potential Vulnerability"), are considered false positives and will not receive disposition commentary from VMware by Broadcom Support.

See KB 414415 for background on why authenticated scanning is not recommended against VCF appliances.

Additional Information

KB 414415 – Authenticated Network Scan of VCF Infrastructure

Minimum Required Versions: 

The minimum required version for VMware Live Site Recovery 9.0.5.

Important Note: Customers using 9.0.x versions must upgrade to 9.1, as these releases do not qualify for review.