CVE program faces swift end after DHS fails to renew contract [updated]
1–10 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#2Re: CVE program faces swift end after DHS fails to renew contract [updated]
#3What are the implications of this? No more centralized store of vulnerability information?
> Hearing a bit more on this. Apparently it's up to the CVE board to decide what to do, but for now no new CVEs will be added after tomorrow. the CVE website will still be up.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#4Re: CVE program faces swift end after DHS fails to renew contract [updated]
#5Is MITRE's CVE program redundant with NIST's National Vulnerability Database? I'm having a hard time telling how the two are related, or if NVD is simply performing the same service as MITRE.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#6Re: CVE program faces swift end after DHS fails to renew contract [updated]
#7I'm trying to steelman but I really can't think of a non- nefarious justification for this
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#8Re: CVE program faces swift end after DHS fails to renew contract [updated]
#9April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann...
NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software and, therefore, vulnerabilities, as well as a change in interagency support.. We are also looking into longer-term solutions to this challenge, including the establishment of a consortium of industry, government, and other stakeholder organizations that can collaborate on research to improve the NVD.
Sep 2024, Yocto Project, "An open letter to the CVE Project and CNAs", https://github.com/yoctoproject/cve-cna-open-letter/blob/mai...> Security and vulnerability handling in software is of ever increasing importance. Recent events have adversely affected many project's ability to identify and ensure these issues are addressed in a timely manner. This is extremely worrying.. Until recently many of us were relying not on the CVE project's data but on the NVD data that added that information.
Five years ago (2019), I helped to organize a presentation by the CERT Director from Carnegie Mellon, who covered the CVE backlog and lack of resources, e.g. many reported vulnerabilities never even receive a CVE number. It has since averaged https://www.youtube.com/watch?v=WmC65VrnBPI