What Information Does the VMware Integration Collect?

Note: The Tenable VMware integration supports both IPv4 and IPv6 environments.

ESXi and vCenter versions

The majority of VMware vulnerability checks are based on the versions of ESXi and/or vCenter. Scans collect the versions of both ESXi and vCenter servers in the target list through an *unauthenticated* API call. Where a vCenter server manages one or more ESXi servers, ESXi version information can also be obtained from the vCenter server — useful when ESXi servers are not routable from the scanner. This path requires successful authentication to the vCenter server.

VMware Installation Bundles (VIBs)

In addition to version information, credentialed scans collect VMware Installation Bundles. Collecting VIBs requires successful authentication to vCenter or ESXi, and in the case of vCenter it also requires Lifecycle Manager permissions (see Required permissions). Collected VIBs are stored in the scanner's Knowledge Base (KB) and are used by the VMware ESX Local Security Checks plugin family. Successful collection of VIBs is the criterion by which an ESXi host may have Credentialed Checks set to yes. Any credential you configure for vCenter or ESXi hosts must be able to list VIBs.

Managed ESXi hosts and virtual machine inventory

With a vCenter credential, the integration enumerates the ESXi hosts vCenter manages and the virtual machines residing on each host, reporting active (powered on) and inactive (powered off) virtual machines against the applicable ESXi host. When Auto-Discovery is enabled, these enumerated ESXi hosts and virtual machines are also added to the scan as additional targets — see Auto-Discovery of ESXi hosts and virtual machines.

What the VMware Integration Does Not Collect

  • The integration does not collect information about the vCenter or ESXi host operating systems.

  • The integration cannot collect full information about the guest operating systems running inside virtual machines (for example, guest OS patch level and installed software).

  • Tenable does not run vulnerability detections against the specific VIB data collected. VIB data supports version-based detections and credentialed-check status.

Note: To assess the vCenter server operating system, configure an additional SSH or Windows credential for the vCenter server. For ESXi hosts, an additional SSH credential is also an alternate method of collecting VIBs. For virtual machines discovered through the integration, configure additional SSH or Windows credentials against each guest operating system you want to assess.