Help Center/ Host Security Service/ FAQs/ Vulnerability Management/ What Do I Do If a Vulnerability Scan Failed?
Updated on 2024-11-15 GMT+08:00

What Do I Do If a Vulnerability Scan Failed?

If a vulnerability scan fails on the HSS console, rectify the fault by following the instructions provided in this section.

Viewing the Cause of a Vulnerability Scan Failure

  1. Log in to the management console.
  2. In the upper left corner of the page, select a region, click , and choose Security & Compliance > HSS.
  3. In the navigation pane, choose Risk Management > Vulnerabilities.

    If your servers are managed by enterprise projects, you can select an enterprise project to view or operate the asset and scan information.

  4. In the upper right corner of the Vulnerabilities page, click Manage Task.
  5. Click the Scan Tasks tab to view vulnerability scan results.
  6. Click View Failure Cause in the Operation column of a failed task to view details.
  7. Handle the vulnerability scan failure based on the failure cause. For details, see Vulnerability Scan Failure Causes and Solutions.

Vulnerability Scan Failure Causes and Solutions

Table 1 Vulnerability scan failure causes and solutions

Failure Cause

Solution

Scan timed out.

Perform the following operations to restart the agent and scan for vulnerabilities again:

  • Windows
    1. Log in to the server as user administrator.
    2. Open the Task Manager.
    3. On the Services tab page, select HostGuard.
    4. Right-click the service and choose Restart.
  • Linux

    Run the following command in the CLI as user root to restart the agent:

    /etc/init.d/hostguard restart

    If the following information is displayed, the restart is successful:
    root@HSS-Ubuntu32:~#/etc/init.d/hostguard  restart
    Stopping Hostguard...
    Hostguard stopped
    Hostguard restarting...
    Hostguard is running

If the scan still fails, choose Service Tickets > Create Service Ticket in the upper right corner of the Huawei Cloud management console to contact technical support.

Agent is in silent or no-load mode.

The agent version is too early.

Upgrade the agent to the latest version and scan for vulnerabilities again.

Asset discovery policy disabled.

Choose Security Operations > Policies, select the policy group that the server belongs to, and check whether the Asset Discovery policy is enabled. If the policy is not enabled, enable it, wait for 10 minutes, and scan for vulnerabilities again.

If the policy is enabled but the scan still fails, choose Service Tickets > Create Service Ticket in the upper right corner of the Huawei Cloud management console to contact technical support.

Failed to execute some detection scripts.

Choose Service Tickets > Create Service Ticket in the upper right corner of the Huawei Cloud management console to contact technical support.

Failed to deliver the scan command.

Try scanning for vulnerabilities again. If the scan still fails after multiple attempts, choose Service Tickets > Create Service Ticket in the upper right corner of the Huawei Cloud management console to contact technical support.

The scan command was lost.

Failed to obtain agent information.

Failed to detect vulnerabilities.

Failed to update vulnerability data.

Failed to update part of vulnerability data.

Failed to load the vulnerability database.

The agent did not report the file list.

Failed to obtain the vulnerability scan status.