GCE 6.0.0 does not detect issues

Hi,

I installed GCE 6, and was surprised to see no results in the scan. I have one device in the network with a default user and no password. In the logs I can see GCE6 log in to the device. The report however does NOT show there are default accounts open.

Greenbone OS 6.0.0 feed from 2 days old
Wed, Nov 20, 2019 10:33 AM UTC
Done RouterOS
Severity 2.6 (Low)
|0|0|3|36|0|

I fired up an old VM I still had, and that DOES show the default account in the reports

Greenbone OS 4.2.24 feed from 50 days old
Wed Nov 20 10:33:48 2019
Done RouterOS
Severity 5.5 (Medium)
|0|4|3|37|0|

for clarity: I deleted all reports on both, and created the same task on both. It’s just the GCE version and the feed that varies. The default accounts is not the only flaw that goes by undetected

is it me or the GCE6 that goes wrong ??

hi @tonsarb,
Could you try with an updated feed in your old VM ? Also, can you tell me the NVT OID or NVT name which produced this result?

1 Like

Hi,

you should always compare the scans with the same feed version. It may be possible that the feed has changed e.g. severities have been updated during the 48 days. Also without knowing the full details about the used scan config and run nvts it is very difficult to compare both scans.

1 Like

Thanks both for replying. I will run both with same (updated) feeds.

However, regardless the outcome of that:
the GCE-6 had the latest feed, it should have reported flaws like admin and root account which neither have a password. and it did not.

Detected by GCE4 with an old feed (and not by GCE6 with new feed) ran against the same device:

  • MikroTik RouterOS File Deletion Vulnerability (CVE-2019-15055)
  • FTP Unencrypted Cleartext Login
  • Telnet Unencrypted Cleartext Login
  • SSH Weak Encryption Algorithms Supported

Ran the feed update and waited for till the “About” box no longer reported a task running. The feeds now are:
GCE-6

NVT Greenbone Community Feed 20191120T1041 Current

SCAP CVEs CPEs OVAL Definitions
Greenbone Community SCAP Feed 20191119T0230 Current

CERT CERT-Bund Advisories DFN-CERT Advisories
Greenbone Community CERT Feed 20191119T0130 Current

GCE-4

NVT Greenbone Community Feed 201911201041 Current

SCAP CVEs CPEs OVAL Definitions
Greenbone Community SCAP Feed 201911190230 Current

CERT CERT-Bund Advisories DFN-CERT Advisories
Greenbone Community CERT Feed 201911190130 Current

I assume the difference -one T in the version number- is just the T preceding time field

Run the scan again on both. Again I see successful and unsuccessful logins from both GCE on the router.

The outcome is still the same as mentioned above; GCE-6 misses the 4 medium results that GCE-4 found.