Updated on 2026-08-24 GMT+08:00

Solution Overview

As enterprises accelerate their digital transformation, servers and business systems carry a large amount of core data and critical services. With cyber threats becoming increasingly sophisticated, system vulnerabilities serve as primary attack vectors, making unpatched flaws a critical security risk. Traditional manual vulnerability audits lack the scale to cover dynamic asset inventories, leading to an extended window of exposure between vulnerability disclosure and remediation. Unpatched vulnerabilities expose enterprises to data breaches, service disruptions, and severe financial damage. Huawei Cloud Host Security Service (HSS) provides an end-to-end vulnerability management solution designed to rapidly detect vulnerabilities, prioritize risks through automated scoring, and streamline remediation to minimize risks.

Vulnerability management is a core capability of HSS. It helps you build a closed-loop workflow across four key stages: vulnerability discovery, assessment, fixing, and verification.

Vulnerability management can scan Linux, Windows, Web-CMS, application, and emergency vulnerabilities. For details about the types of vulnerabilities that can be scanned in different editions, see Vulnerabilities Supported by HSS.

The HSS vulnerability management plan consists of the following parts:

  1. Preparations: Vulnerability management depends on asset management, vulnerability management, and baseline check features. Before you start, purchase an HSS edition that supports required features and identify your asset scope. For details, see Editions.
  2. Detecting and Fixing Vulnerabilities: Enable vulnerability scan, assess the vulnerability fixing priorities, develop a remediation plan, and fix and verify vulnerabilities. Perform baseline checks to identify misconfigurations and harden systems accordingly.
  3. Recommended Actions: Check vulnerability management reports, analyze the trends and issues, adjust scan policies and priorities, and maintain continuous monitoring to enforce closed-loop security operations.