When checking for missing packages, sshupdate server component should create lists of CVE:s that a machine is vulnerable to by grabbing that from rpm changelog
Ex:
rpm -q --changelog kernel-2.6.32-358.23.2.el6.x86_64
yum-changelog might also be of interest for this.