Vulnerability database (VDB) updates

The VDB is a database of known vulnerabilities to which hosts may be susceptible, as well as fingerprints for operating systems, clients, and applications. The system uses the VDB to help determine whether a particular host increases your risk of compromise.

VDB versions

We periodically release VDB updates. Each update replaces the previous version.

Starting with VDB 357, you can install an earlier VDB as far back as the baseline VDB for Cloud-Delivered Firewall Management Center.

VDB update duration

The time required to update the VDB and its associated mappings on the Cloud-Delivered Firewall Management Center depends on the number of hosts in your network map. Allow approximately one minute for every 1000 hosts.

Scheduled VDB updates

Initial configuration automatically downloads and installs the latest VDB as a one-time operation and creates a weekly task to download future updates. Review the schedule and adjust as needed. To update the VDB and deploy configurations automatically, create separate tasks. For more information, refer to Scheduling.

Deployment after VDB updates

Deploy configuration changes after a VDB update for updated application detectors and operating system fingerprints to take effect. Updated vulnerability information takes effect without deploy.

Caution

The first deploy after a VDB update usually restarts Snort because updated application detectors and operating system fingerprints require a restart. Restarting Snort briefly interrupts traffic flow and inspection on all devices, including those configured for high availability or scalability. Interface configurations determine whether traffic drops or passes without inspection during the interruption. When you deploy without restarting Snort, resource demands may result in a small number of packets dropping without inspection.

VDB release information

For VDB 343 and later, Cisco Secure Firewall Application Detectors provides searchable application detector information. The release notes describe changes in each VDB release.

VDB lite

For the Secure Firewall 220, the system installs a smaller VDB (also called VDB lite). This smaller VDB contains the same applications, but fewer detection patterns. Devices using the smaller VDB can miss some application identification versus devices using the full VDB.