Manually download and add firmware vulnerability files
Firmware vulnerability data from the National Institute of Standards and Technology (NIST) is available if you have a license for NCM or SolarWinds Observability Self-Hosted Advanced. Firmware vulnerability data is routinely updated to reflect new threats. By default, the latest data is automatically retrieved from NIST, stored on solarwinds.com, and downloaded to your server based on the settings you specify.
If you are on a closed network and firmware vulnerability data cannot be automatically downloaded from solarwinds.com, complete the following steps to get the latest data. Repeat this regularly to update the data.
If you have High Availability (HA) backup servers configured, perform this procedure on both your main polling engine and your HA backup servers.
-
From a computer with Internet access, download the following firmware vulnerability .zip files:
-
Copy each
.zip
file to a location on your SolarWinds Observability Self-Hosted server. -
Open the CVE Data Import Settings, and replace the following URLs with the location of the
.zip
files:-
Under Manage Data Sources, specify the path to
cve-all.json.zip
. -
Under CPE Match Feed, specify the path to
cpematch.json.zip
.
-