Manually download and add firmware vulnerability files
NCM ships with initial firmware vulnerability data. However, firmware vulnerability data is routinely updated to reflect new threats. To ensure that you have the latest data, NCM automatically retrieves the latest data from NIST, stores it on solarwinds.com, and downloads it to your server based on the settings you specify.
If NCM cannot automatically download firmware vulnerability data (for example, because you are on a closed network), you can download vulnerability data files from a different server and then manually add them to your NCM server. NCM will use the information in these files to search for vulnerabilities that could affect your devices.
If you have High Availability (HA) backup servers configured, perform this procedure on both your main polling engine and your HA backup servers.
-
Download the following firmware vulnerability .zip files:
-
Log in to your NCM server.
-
Extract the contents of the
cve-all.json.zip
file into the following folder:C:\ProgramData\SolarWinds\NCM\Vuln\Json
. -
Extract the contents of the
cpematch.json.zip
file to the\CpeMatch
directory within that folder:C:\ProgramData\SolarWinds\NCM\Vuln\Json\CpeMatch
-
Under Vulnerability Search Settings, click Run Now.