---
title: "Find which shipped machines a new CVE exposes | Edge SDN"
description: "How a machine builder can tell, in minutes, which delivered machines a new vulnerability exposes, and why a CVE list per model gives the wrong answer."
url: https://www.edge-sdn.com/use-cases/find-which-machines-a-new-cve-exposes/
last_updated: 2026-09-19
---

Cyber Resilience Act · Machine builder · System integrator

# Same model, two machines, one exposed: find which shipped machines a new CVE hits

By Aldo Campi, co-founder and CEO of Stoorm5 · Published 19 September 2026 · Last updated 19 September 2026

How do I manage vulnerabilities across the machines I have already installed at customers?

Keep a component list (SBOM) and an attack surface for each delivered machine, not only for each model. When a new CVE is published, match it to the components, then check if the vulnerable part can be reached through the ports and protocols of that machine. Only machines where both are true are exposed.

Where are you against 20 January 2027? [Take the Check 2027](https://www.edge-sdn.com/check-2027/): seven questions, three minutes.

## Key facts

- The CRA asks manufacturers to identify and document the components in their products, including a software bill of materials in a machine-readable format. [\[Regulation (EU) 2024/2847, Annex I, Part II, point 1\]](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng)
- Since 11 September 2026 a manufacturer must report an actively exploited vulnerability within 24 hours and inform the affected users. [\[Regulation (EU) 2024/2847, Article 14\]](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng)
- Products must be delivered without known exploitable vulnerabilities from 11 December 2027. [\[Regulation (EU) 2024/2847, Annex I, Part I\]](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng)

## The situation

A packaging machine builder has delivered 47 machines of three models to 12 customers. One of those customers, a pharmaceutical company, runs two X-200 labelling machines side by side on the same line.

On a Tuesday morning a critical vulnerability is published. It affects the firmware of a VPN gateway that the builder uses for remote maintenance. The score is 9.1 out of 10.

The builder now has four questions and very little time:

1. Which of the 47 machines contain that gateway, with that firmware version?
2. On which of those machines can the gateway be reached from outside?
3. Which customers should we inform, and what do we tell them to do?
4. How do we prove later that we did all this on time?

If the vulnerability is actively exploited, Article 14 of the CRA makes the report to the authorities and the notice to users a duty.

## Why the usual tools give the wrong answer

Most vulnerability tools work from a list of components. They tell you: “the X-200 model uses this gateway, so the X-200 is vulnerable.” The builder then alarms every customer that owns an X-200.

This answer is wrong twice.

First, **delivered machines are not identical**. In our example the second X-200 at the same customer was delivered six months later with a gateway from another supplier. It is not affected at all.

Second, **vulnerable does not mean exposed**. The gateway is only reachable in remote maintenance and software update mode, which together are open about 10% of the time. A machine whose remote maintenance is permanently closed by the customer’s firewall has the same component and a very different risk.

Making this judgment by hand means reading the CVE description, understanding which function is vulnerable and comparing it with the network configuration of each machine. With 15 components per machine and new CVEs every day, nobody has the time. People who can do it well are rare and expensive.

## The steps to solve it

### 1. Keep a record per serial number

For each delivered machine, record the customer, the plant, the components with their exact versions and the install date. Hardware firmware and software libraries go in the same list. This is the SBOM of the machine.

### 2. Describe how the machine can be reached

List the operating states of the machine (production, local maintenance, remote maintenance, software update). For each state, note the network flows that are open and how much of the time the state is active. This is the attack surface.

### 3. Match new CVEs every day

Check the public vulnerability databases daily against the components of every machine. This part is easy to automate and many tools do it.

### 4. Judge exposure per machine

For each match, decide if the vulnerable part can be reached through the declared flows. Record the judgment and the reason in plain language. This is what a VEX statement contains.

### 5. Act only where it matters

If the machine is not exposed, record it and issue an updated report. Nobody has to do anything. If it is exposed, alert the engineer in charge and prepare the notice for that customer, with the technical report and the patch procedure.

## How Shield Lifecycle does it

[Shield Lifecycle](https://www.edge-sdn.com/products/shield-lifecycle/) runs this loop for you. In our demo the result arrives in minutes:

- Machine X200-2024-001 drops from a health score of 90 to 68. The gateway is exposed in two operating profiles. A notice to the customer is drafted with the documents attached.
- Machine X200-2024-002 stays at 90. It has a different gateway.
- The other 45 machines are checked. Those with the gateway but with remote maintenance blocked are marked as not exposed, with the reason.

The customer sees the same information in their own portal and downloads the updated reports.

## What Shield Lifecycle does not do

It does not patch the machine and it does not replace your engineers’ decision on how to fix the problem. It is vendor-agnostic: it works with whatever firewall or switch protects the machine. If the fix is on the network side, [Edge Shield](https://www.edge-sdn.com/products/edge-shield/) is one option.

## Frequently asked questions

### What is the difference between a vulnerable machine and an exposed machine?

A machine is vulnerable when one of its components has a known CVE. It is exposed when an attacker can actually reach that component through the network flows that are open on that machine. Many vulnerable machines are not exposed.

### What is VEX?

VEX means Vulnerability Exploitability eXchange. It is a machine-readable statement that says if a product is affected by a given vulnerability, and why. It is the natural companion of an SBOM.

### Why is a CVE list per machine model not enough?

Because delivered machines differ. A customer asks for a different gateway, a supplier changes a firmware version, a technician opens a port during commissioning. The model is the same and the exposure is not.

Product

### Shield Lifecycle

[Explore Shield Lifecycle](https://www.edge-sdn.com/products/shield-lifecycle/)

Related use case

### Reduce the attack surface of an old machine: protect what you cannot patch

[Read](https://www.edge-sdn.com/use-cases/protect-a-machine-you-cannot-patch/)

Related use case

### Report to ENISA in 24 hours: what a machine builder must do since 11 September 2026

[Read](https://www.edge-sdn.com/use-cases/report-to-enisa-in-24-hours/)

This article is a summary for practitioners and not legal advice. Always check the official text for your case.

## Where are you against 20 January 2027?

Seven questions about how you work today. Three minutes. You get a score out of 10 and what is missing for you.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026
