Managing Vulnerabilities & Patches
How Sentrivox correlates CVEs to your assets, prioritizes with CVSS and EPSS scores, and helps you remediate the vulnerabilities that matter most.
How Sentrivox finds vulnerabilities
Sentrivox knows exactly what software and patches are installed on every endpoint. It continuously matches that inventory against public vulnerability data — including the NVD (National Vulnerability Database), CISA's Known Exploited Vulnerabilities (KEV) catalog, and vendor advisories — to identify which CVEs actually affect your machines.
Prioritization: not all CVEs are equal
A typical fleet has thousands of theoretical vulnerabilities — far more than any team can patch at once. Sentrivox helps you focus on what actually matters using two scores:
- CVSS — the severity of a vulnerability if exploited (how bad the impact is).
- EPSS — the probability that a vulnerability will actually be exploited in the wild (how likely it is).
Combining severity with real-world exploit likelihood — and highlighting anything on CISA's KEV list of actively exploited flaws — lets you fix the handful of vulnerabilities that pose real risk before chasing the long tail of low-probability ones.
Working through the vulnerabilities view
The Vulnerabilities section lists findings prioritized by risk. For each one you can see:
- The affected software and version.
- Which endpoints are impacted.
- CVSS severity, EPSS likelihood, and whether it’s a known exploited vulnerability.
- The fix — typically a patch or version upgrade.
Remediation
Most vulnerabilities are resolved by applying the relevant patch or upgrading the affected software. Once the endpoint updates and the agent reports the new version on its next heartbeat, Sentrivox automatically clears the finding — so your vulnerability list always reflects reality.
