Earlier quoted context omitted.
If you don't assign CVE numbers to every security-related flaw, no matter how minor the flaw may be, you must come up with a way to draw the line on what flaws get CVEs and what ones don’t. That would be worse in pretty much every respect. As it is now, I can look at a CVE and determine for myself and my organization whether it something we need to care about. I’d rather that decision stay in my hands, not someone el…
> I can look at a CVE and determine for myself and my organization whether it something we need to care about. Except it doesn't work like this. A security scanner will include a CVE. People want no red flags on the security scanner. They don't care what the CVE is, they just want red mark go away. The attitude to accepting useless crap as a CVE is diluting what an important CVE actually is.
You'll have to email my bosses that :)