Security8 min read

Managing Vulnerabilities & Patches

How Sentrivox correlates CVEs to your assets, prioritizes with CVSS and EPSS scores, and helps you remediate the vulnerabilities that matter most.

How Sentrivox finds vulnerabilities

Sentrivox knows exactly what software and patches are installed on every endpoint. It continuously matches that inventory against public vulnerability data — including the NVD (National Vulnerability Database), CISA's Known Exploited Vulnerabilities (KEV) catalog, and vendor advisories — to identify which CVEs actually affect your machines.

ℹ️
No credentialed scanning needed
Because the agent already has an accurate software inventory, Sentrivox correlates vulnerabilities without running noisy network scans or storing credentials for every device.

Prioritization: not all CVEs are equal

A typical fleet has thousands of theoretical vulnerabilities — far more than any team can patch at once. Sentrivox helps you focus on what actually matters using two scores:

  • CVSS — the severity of a vulnerability if exploited (how bad the impact is).
  • EPSS — the probability that a vulnerability will actually be exploited in the wild (how likely it is).

Combining severity with real-world exploit likelihood — and highlighting anything on CISA's KEV list of actively exploited flaws — lets you fix the handful of vulnerabilities that pose real risk before chasing the long tail of low-probability ones.

💡
Start with KEV + high EPSS
Vulnerabilities that are on the KEV catalog or have a high EPSS score are being exploited right now. Patch these first, regardless of raw CVSS.

Working through the vulnerabilities view

The Vulnerabilities section lists findings prioritized by risk. For each one you can see:

  • The affected software and version.
  • Which endpoints are impacted.
  • CVSS severity, EPSS likelihood, and whether it’s a known exploited vulnerability.
  • The fix — typically a patch or version upgrade.

Remediation

Most vulnerabilities are resolved by applying the relevant patch or upgrading the affected software. Once the endpoint updates and the agent reports the new version on its next heartbeat, Sentrivox automatically clears the finding — so your vulnerability list always reflects reality.

Related articles

Still need help?

Our team is here to help you get the most out of Sentrivox. Reach out any time and we'll get back to you fast.

Contact Support →Request a Demo