When a target is deployed in the field, usually is never updated, not even for security fixes. What I'm proposing is to have a service in the target that checks the current packages and versions used, then compare with a list of vulnerable packages and versions; if the target is using a vulnerable software then notify the vendor/user. This won't automatically do the software update on the field but I think is a step in the right direction.
Also please review the existing meta-security layer which has some other runtime testing tools.
there is a way of doing this. basically OVL files via openscap to run. this works. recipes in meta-security. Its generating the OVL files. This also creates html reports.
As Armin mentioned there is a solution in meta-security. There are other solutions provided by companies.