False Positive Vulnerabilities - Still Showing After Fix Applied - Resource is Blank In Console
search cancel

False Positive Vulnerabilities - Still Showing After Fix Applied - Resource is Blank In Console

book

Article ID: 378931

calendar_today

Updated On:

Products

Carbon Black Cloud Workload Carbon Black Cloud Endpoint Standard (formerly Cb Defense)

Issue/Introduction

  • When looking at the vulnerabilities, there is no "Resource" listed
  • Recommended fix has been applied, but vulnerability still shows

Environment

  • Carbon Black Cloud Sensor: All Supported Versions
  • Carbon Black Cloud Console: Vulnerability Management

Cause

  • CVE does not a specific update (KB) or fixed version associated with it
  • Fix includes manual manipulation of the device (such as the editing of a registry key)
    • Carbon Black Cloud does not manually validate registry keys

Resolution

The "Dismiss" function can be utilized for false positives as described in the Dismissing Vulnerabilities section of Tech Docs.