Scan Results Review
This section helps you interpret the results of your VMware vCenter API and VMware ESX SOAP API scans.
Plugin families and plugins
The following Tenable plugins are relevant when reviewing scan results with the VMware integration.
Misc. plugin family:
-
Plugin #204872: Integration Status. When using a Tenable integration with any PAM Integration, the Integration Status plugin confirms whether credential retrieval succeeded or failed.
General plugin family:
-
Plugin #168417: Integration Discovered Host — reports targets that were added to the scan by an integration's auto-discovery feature. vCenter is a Tenable integration that supports auto-discovery of ESXi hosts and virtual machine hosts.
Settings plugin family:
-
Plugin #19506: Nessus Scan Information — see the following Caution. This plugin's Credentialed Checks value reflects VIB collection, not host login.
Caution: Tenable has observed user confusion about Credentialed Checks: yes/no in plugin 19506 and how authentication is interpreted for the VMware integrations. In a traditional SSH or Windows scan, that value reflects whether login credentials to the target machine were valid. With the VMware integrations, Tenable authenticates to the vCenter or ESXi *API* — not the host machine. Unless an SSH credential is included alongside the VMware credential, expect Credentialed Checks: yes if the integration collected VIBs for that host and no if it did not. When scanning vCenter-managed ESXi hosts with API credentials, the vCenter host's own results always show Credentialed Checks: No.
Service Detection plugin family:
-
Plugin #63061: VMware vCenter Detect — gathers the vCenter version from an unauthenticated SOAP API call to the vCenter host. Even later versions (7.0.3+) maintain a SOAP API. The version this plugin gathers feeds vCenter vulnerability detection plugins that rely on versioning, and determines whether the integration collects vCenter and ESXi data via the SOAP API (earlier than 7.0.3) or the REST API (7.0.3+). This plugin runs independently of the integration and is not indicative of vCenter authentication issues.
-
Plugin #57396: VMware vSphere Detect — gathers the ESXi version from an unauthenticated SOAP API call to the ESXi host. The version feeds ESXi vulnerability detection plugins that rely on versioning. This plugin runs independently of the integration and is not indicative of authentication issues.
VMware ESX Local Security Checks plugin family:
-
Plugin #63062: VMware vCenter Data Collection — handles authentication to the vCenter REST API and collection of vCenter-managed ESXi hosts, ESXi VIBs, ESXi-managed virtual machines, and virtual machine details, for vCenter and ESXi 7.0.3+. Collection and storage execute against only one target in the scan and are reused for reporting on subsequent enumerated targets.
-
Plugin #180178: VMware vCenter Legacy Data Collection — the equivalent plugin for the vCenter SOAP API, used for vCenter and ESXi versions earlier than 7.0.3.
-
Plugin #180179: VMware vCenter Auto-Discovery — executes the auto-discovery process when Auto-Discovery of ESXi hosts and virtual machines is enabled.
-
Plugin #154017: VMware vCenter Managed ESXi Installed VIBs — reports the installed VIBs collected on a vCenter-managed ESXi host. Credentialed Checks status and version-based detections depend on successful VIB collection. Tenable does not run vulnerability detections against the specific VIB data itself.
-
Plugin #57400: VMware vSphere Installed VIBs — reports the installed VIBs collected directly on an ESXi host through the ESX SOAP API.
-
Plugin #84340: VMware vCenter Active Virtual Machines — reports powered-on virtual machines collected for a specific ESXi host, reported against that ESXi host.
-
Plugin #84341: VMware vCenter Inactive Virtual Machines — reports powered-off virtual machines collected for a specific ESXi host.
-
Plugin #57397: VMware Active Virtual Machines — the ESX SOAP API equivalent for powered-on virtual machines.
-
Plugin #57398: VMware Inactive Virtual Machines — the ESX SOAP API equivalent for powered-off virtual machines.
Note: In addition to these integration-related plugins, ESXi vulnerability detection plugins belong to the VMware ESX Local Security Checks plugin family. If this plugin family is disabled, scan results do not include those vulnerability detections.
Policy Compliance plugin family:
-
Plugin #64455: VMware vCenter/vSphere Compliance Checks — must be enabled to execute compliance scanning and performs compliance checks against both vCenter and ESXi hosts.