I’m trying to understand the folowing. I have an NVT job scheduled every week for a set of webservers. It’s configured with the default Full and fast scan config. A VCE job is scheduled every day with the same scan target webservers. The CVE detects some vulnarabilities based on the discovered product, however this product version does not reflect the actual version. The particular webserver has been updated a few days back and has (confirmed) a higher version, we have run the NVT job post version upgrade.

Looking at the CVE report it states:

Detection Method
Version used:

Does this reflect the discovery date?

I have read the docs, but I cant seem to find how often the Full and fast does a new discovery or that it even do a discovery. I hope someone can clarify this for me.

It might be possible that after the recent web server update either the web server isn’t detected anymore at all or the version isn’t exposed anymore. Not sure how GVM is handling this case internally.

Before starting this topic I’ve created a separate task and target to this specific webserver. This task determines the new version just fine. So it’s not such case.

We need to determine the discover logic of a Full and fast task.

Hello, could anyone please give us some insights regarding this issue?