Home / Companies / Socket / Blog / Post Details
Content Deep Dive

NVD Remains Stalled on Enriching CVE's, Security Industry Cr...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
1,048
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

The National Institute of Standards and Technology (NIST) is facing criticism from the cybersecurity industry over delays in enriching Common Vulnerabilities and Exposures (CVE) records in the National Vulnerability Database (NVD), a crucial component of the nation's cybersecurity framework. These delays are attributed to an increase in software vulnerabilities and changes in interagency support, resulting in a significant backlog of unprocessed vulnerabilities. In response, NIST plans to establish a consortium to address these challenges, although this has been met with skepticism and calls for clearer communication. Security professionals have expressed concerns about the lack of transparency and are urging Congress to investigate and ensure sufficient resources for the NVD, even suggesting its potential transfer to the Cybersecurity and Infrastructure Security Agency (CISA). Meanwhile, third-party initiatives like Anchore's open-source "NVD Data Overrides" project are emerging to fill gaps left by the NVD's stalled enrichment efforts, though they lack the official severity scores that only the NVD can provide.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.