CISA Launches Vulnrichment Project as NVD Backlog Hits 10,00...
Blog post from Socket
CISA has launched the Vulnrichment project to enhance Common Vulnerabilities and Exposures (CVEs) with detailed information such as severity and exploitability, aiming to aid organizations in prioritizing patching and mitigation efforts amidst a growing backlog of over 10,000 unenriched CVEs at the National Vulnerability Database (NVD). The project, unveiled at RSA, incorporates Common Platform Enumeration, Common Vulnerability Scoring System, Common Weakness Enumeration, and Known Exploited Vulnerabilities into the CVEs, and although the NVD halted its enrichment efforts in February, the Vulnrichment project seeks to address the backlog by enriching a subset of CVEs using CISA’s Stakeholder-Specific Vulnerability Categorization (SSVC). CISA has already enriched 1,300 CVEs and encourages CVE Numbering Authorities to submit comprehensive CVEs, with the enriched data made freely available under a CC0-1.0 license. However, the project faces challenges with conflicting Common Platform Enumeration (CPE) strings, which complicates automation efforts, and while CISA has not explicitly stated it is replacing NVD, it is clear they are attempting to manage the backlog, with enriched data accessible via GitHub. The initiative is anticipated to evolve quickly, focusing on new and high-risk CVEs, and aims to eventually reintegrate the data into the main CVE corpus.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.