An endpoint previously had a vulnerability for an application flagged by FortiClient vulnerability scan.
The application has since been uninstalled and the vulnerability is not being detected.
However the application is still showing in the Software Inventory. It has been a number of weeks and I can confirm multiple vulnerability scans have since been ran as expected.
This issue is occurring with multiple applications but for this application in particular I can see that a vulnerability is no longer detected. I cannot find any executables for the applications on the endpoint.
Along side uninstall is there anything else to do to ensure an application is removed from the Software Inventory?
If this is an issue is there a location I could provide the application name for further review? I'm curious if this is linked to Issue 73790 for 7.2.4 but just wanted to ensure I've covered all checks from my side.
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello Register244,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for someone to help you.
We will come back to you ASAP.
Regards,
Are you sure the application is completely removed from the end host? You can try to export the application list as raw and check the application path to see if there is any remaining file in the end host.
Hi ebilcari,
Yes, the folders related to the applications have been deleted.
The applications CSV file has an entry for the applications on the endpoint (For example: C:\Program Files...) however I have confirmed the folders don't exist on the endpoint.
If I search for the applications using the Windows 'Search This PC' feature no files or folders related to the applications are returned.
The applications are not listed in 'Add or Remove Programs' under Windows system settings.
Thanks
Hi
You are right, this looks much like bug id:
737970 | Software Inventory on EMS does not properly reflect software changes (adding/deleting) on Windows endpoints. |
I'd also try search in registry editor if any residual info left by application, just in case.
I have the same issue.
1) How can I find the status of the bug (737970) that you listed
2) What is the ETA to resolving this bug
3) If already resolved, how can I force the software inventory to only report on current applications?
Hello
According to release note documents, it seems the issue is not resolved yet on version 7.2.x. Nevertheless the bug is not mentioned anymore in release 7.4.0.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1073 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.