Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

1–10 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#3

What are the implications of this? No more centralized store of vulnerability information?

According to Brian Krebs: https://infosec.exchange/@briankrebs/114343835430587973

> Hearing a bit more on this. Apparently it's up to the CVE board to decide what to do, but for now no new CVEs will be added after tomorrow. the CVE website will still be up.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#5

Is MITRE's CVE program redundant with NIST's National Vulnerability Database? I'm having a hard time telling how the two are related, or if NVD is simply performing the same service as MITRE.

NIST NVE relies on the CVE program. (vulnerabilities get reported, MITRE assigns CVEs and publishes them, NIST then copies that list and adds their own scoring etc to it)

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#9
If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year.

April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann...

  NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software and, therefore, vulnerabilities, as well as a change in interagency support.. We are also looking into longer-term solutions to this challenge, including the establishment of a consortium of industry, government, and other stakeholder organizations that can collaborate on research to improve the NVD.
Sep 2024, Yocto Project, "An open letter to the CVE Project and CNAs", https://github.com/yoctoproject/cve-cna-open-letter/blob/mai...

> Security and vulnerability handling in software is of ever increasing importance. Recent events have adversely affected many project's ability to identify and ensure these issues are addressed in a timely manner. This is extremely worrying.. Until recently many of us were relying not on the CVE project's data but on the NVD data that added that information.

Five years ago (2019), I helped to organize a presentation by the CERT Director from Carnegie Mellon, who covered the CVE backlog and lack of resources, e.g. many reported vulnerabilities never even receive a CVE number. It has since averaged https://www.youtube.com/watch?v=WmC65VrnBPI

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#10
post #8
post #7

Earlier quoted context omitted.

[flagged]

Yet so far no volunteer has emerged and people who do run CNA are pretty busy with it.

I think sneak would volunteer to do it since it is pretty simple according to them.
Post reply on HN