CVE Scanner
The CVE Scanner checks your Proxmox nodes for known security vulnerabilities by comparing installed packages against public CVE databases. It helps you identify and prioritize patching for critical vulnerabilities before they can be exploited.
Overview
ProxCenter connects to each Proxmox node via SSH, reads the list of installed Debian packages and their versions, and cross-references them against known CVE records. The results show which packages have known vulnerabilities, the severity of each CVE, and whether a patched version is available.
How It Works
- ProxCenter reads the installed package list from each node over SSH (
dpkg -l) - Package names and versions are compared against the Debian Security Tracker and NVD (National Vulnerability Database)
- Matching CVEs are returned with their severity score, description, and fix status
No software is installed on the Proxmox nodes -- the scan is read-only and non-intrusive.
Network requirements
The Debian data is downloaded by the orchestrator, not by the nodes: the security tracker from https://security-tracker.debian.org and the package sources from https://deb.debian.org, over HTTPS. The orchestrator needs a route to both, directly or through an HTTP proxy. The containers do not inherit the proxy of the Docker daemon, so behind a proxy, give it to the orchestrator as described in Installing behind an HTTP proxy. Without that route, the scan ends with Scan failed.
What the Scan Covers, and What It Says When It Cannot
Until v1.4.10 the scan read the Proxmox API's update endpoints, which report the handful of packages Proxmox itself tracks and leave most of the Debian base system out. It now reads the node's real installed package list over SSH, and falls back to the Proxmox API only when SSH is not available.
The header states the coverage of every scan: "N packages scanned, M known to the Debian security tracker". A scan that could only read part of the estate carries a Partial scan chip and names the reason per node, rather than rendering the same green "No vulnerabilities detected" as a healthy cluster:
| Reason | What it means |
|---|---|
| SSH is not configured on this connection | Only the packages the Proxmox API reports were scanned. Most of the Debian base system is left out |
| The package inventory over SSH failed on a node | The scan fell back to the Proxmox API for that node and covers only part of its packages |
| The SSH credentials of this connection could not be read | Same fallback, for the same reason |
| The Debian security tracker no longer publishes data for this release | That node cannot be scanned at all |
| The node is offline | It was not scanned |
A scan that failed outright shows Scan failed with its cause and a retry, instead of an empty result. Reading an orchestrator older than this release, the coverage line and the partial-scan chip simply do not appear.
The difference is not marginal. Without SSH the scan sees what Proxmox reports as updatable; with it, every package dpkg knows about. A connection without SSH is the single most common reason a CVE report looks suspiciously short.
Scan Results
For each node, the scanner displays:
| Field | Description |
|---|---|
| CVE ID | The unique CVE identifier (e.g., CVE-2024-1234) |
| Package | The affected Debian package name |
| Installed Version | The version currently installed on the node |
| Fixed Version | The version that resolves the vulnerability (if available) |
| Severity | CVSS score and severity level (Critical, High, Medium, Low) |
| Node | The node the affected package is installed on |
| Published | When the CVE was published |
| Description | Brief description of the vulnerability |
Results can be sorted by severity, package name, or CVE date, and a long list is paginated. A summary card at the top shows the total count by severity level.
CVEs with no published fix carry a No fix yet chip and their own filter, and are out of the default view. There is nothing to patch for them, so leaving them in the main list buried the CVEs an operator can actually act on.
Scheduling Scans
You can run scans on demand or schedule them to run automatically:
- On demand -- Click Scan Now on any node or across all nodes
- Scheduled -- Configure a recurring scan (daily, weekly) from the scanner settings
Scan results are stored historically, so you can track your patching progress over time.
After applying system updates to a node, run a new scan to verify that the patched packages are reflected in the results. The previous scan results remain available for comparison.
Filtering and Export
- Filter by severity -- Focus on critical and high vulnerabilities first
- Filter by fix status -- The default view shows the CVEs that have a fix available, which are the actionable ones. No fix yet brings back the rest
- Export -- Download the scan results as CSV for reporting or compliance documentation
The CVE Scanner needs SSH access to each Proxmox node to read the full package list. A node it cannot reach over SSH is either scanned through the Proxmox API, with far narrower coverage, or skipped, and the result says which.
The CVE Scanner is available in the Enterprise edition.
Permissions
| Permission | Description |
|---|---|
security.view | View CVE scan results |
security.manage | Run CVE scans and configure schedules |