2 Read Before Use

2.1 Using a Supported GOS Version

OPENVAS SCAN should always be operated with a GOS version supported by Greenbone, including the corresponding patch level. Otherwise, the following issues may occur:

  • Incompatibilities in the feed

  • Unfixed bugs

  • Missing functionality (for example functionality required for VTs to work reliably or at all)

  • Decreased scan coverage or missing vulnerability detection due to the issues mentioned above

  • Unfixed security vulnerabilities in the components used (for example, GOS)

2.2 Effects on the Scanned Network Environment

OPENVAS SCAN includes a full-featured vulnerability scanner. While the vulnerability scanner has been designed to minimize any adverse effects on the network environment, it still needs to interact and communicate with the target systems being analyzed during a scan.

Note

It is the fundamental task of OPENVAS SCAN to find and identify otherwise undetected vulnerabilities. To a certain extent, the scanner must behave like cyberattackers would.

While the default and recommended settings minimize the impact of the vulnerability scanner on the environment, unwanted side effects may still occur. Users can control and adjust the scanner behavior using the available scanner settings.

Note

The following general side effects may occur:

  • Log and alert messages may show up on the target systems.

  • Log and alert messages may show up on network devices, monitoring solutions, firewalls and intrusion detection and prevention systems.

  • Firewall rules and other intrusion prevention measures may be triggered.

  • Scans may increase latency on the target or the scanned network, or both. In extreme cases, this may result in situations similar to a denial-of-service (DoS) attack.

  • Scans may trigger bugs in fragile or insecure applications resulting in faults or crashes.

  • Embedded systems and operational technology (OT) devices with weak network stacks may be particularly susceptible to crashes or even device failure.

  • The scanner performs login attempts (for example, via SSH or FTP) on target systems for banner-grabbing purposes.

  • The scanner sends probes via different protocols (for example, HTTP, FTP) to all exposed services for service detection.

  • Scans may result in user accounts being locked due to the testing of default user name/password combinations.

Since the behavior described above is expected, desired, or even required for vulnerability scanning, the scanner’s IP addresses should be added to the allowlist of the affected system or service. Information on creating such an allowlist is available from the documentation or support of the respective system or service.

Remember that triggering faults, crashes, or account lockouts with default settings means that cyberattackers can do the very same at any time and to an unpredictable extent.

While the side effects are very rare when using the default and recommended settings, the vulnerability scanner allows the configuration of invasive behavior and thus may increase the likelihood of the effects listed above.

Note

Be aware of these facts and ensure the required authorization to execute scans before using OPENVAS SCAN to scan the target systems.

2.3 Scanning Through Network Equipment

2.3.1 General Information

Scanning through network equipment such as an IDS (Intrusion Detection System)/IPS (Intrusion Prevention System), a WAF (Web Application Firewall), a proxy, or a firewall should be avoided, as such devices may interfere with the scan, which may lead to unpredictable scan behavior or effects on the network environment, including:

  • False-positive and false-negative results

  • Reduced scan performance

  • Too many ports reported as open on the scan target

  • Dropped packets due to TCP connection limits or maximum session limits being reached

  • Depending on the settings, large volumes of log data may be generated, which can lead to an overload of the log server or – if logging is completely disabled – to a blind spot.

Note

Such behavior can also occur if the maximum number of checks per host is limited.

2.3.2 Firewall-Specific Information

Depending on the specific product, a firewall may have several additional modules such as deep packet inspection and denial-of-service (DoS) protection.

  • These modules may have limited configuration options, such as enabling or disabling them only per interface and not per source/target IP address.

  • Some of the modules may even be hidden or not configurable at all, so that the side effects mentioned above may occur without it being apparent which module caused them.

  • The load on the firewall will increase significantly. In the worst case, connections are not only interrupted for the scanner, but the entire firewall functionality can be impaired, which can lead to a denial of service.

2.4 Technology Previews

Technology Preview features are early-access capabilities that allow customers to evaluate upcoming functionality and provide feedback before general availability.

Technology Preview features have the following key characteristics and limitations:

  • They are not fully supported and may be incomplete, unstable, or unsuitable for production use.

  • They may be significantly changed, replaced, moved to a different product offering, or discontinued without replacement.

  • They are provided for evaluation, validation of direction, and usability testing, not as production-ready functionality.

  • Compatibility, upgrade, and migration paths are not guaranteed.

  • Future generally available (GA) versions may require reinstallation, reconfiguration, or manual data migration.

  • Issues related to Technology Preview features are handled on a best-effort basis and are not subject to standard support expectations for fully supported features.

  • Customer feedback may be used to improve future releases.

  • Greenbone may make reasonable efforts to review reported issues.

Note

Customers should not rely on Technology Preview features for production environments or long-term planning.