-
-
Notifications
You must be signed in to change notification settings - Fork 245
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE bin tool integration, VEX support -> F20 replacement #1452
Conversation
initial test results:
35minutes vs 1h:40minutes ... Feel free to test |
I think everything is in place to find further bugs ... please give it a try @BenediktMKuehne @beruhan @torabi12 @hands0meware @busby666 and others :) |
The main performance boost can be seen if you enable/disable the VEX_METRICS parameter in the scan profiles:
On the other hand you will loose all the exploit details. |
let's review this and bring it to master :) VEX SBOM and cve-bin-tool ahead ... |
I did an installation and it was perfect and did a default-scan.emba with an older DVR firmware from here: https://www.up-4ever.net /ecs3xzneqmnw/Firmware_DVR_8CH_China_AHB6008R-MS_8MB.rar VEX data was available in the report. The entire scan lasted for 00:27:08, super fast! |
@torabi12 thank you for your testing effort |
Feature
F20 quite slow
No VEX support
This will replace the current F20 module
docker base image 1.5.1d needed
Currently work in progressread only filesystem of our current docker base image is currently not working with cve-bin-tool