What’s going on with the National Vulnerability Database? (2024)

The National Vulnerability Database is so overwhelmed with a steadily increasing number of software and hardware flaws that the National Institute of Standards and Technology, which maintains the common vulnerabilities and exposures repository, called for a slight pause to regroup and reprioritize its efforts.

NIST scaled back the NVD program in mid-February, and is currently prioritizing analysis of the most significant or actively exploited vulnerabilities. The slowdown was precipitated by “an increase in software and, therefore, vulnerabilities, as well as a change in interagency support,” NIST said in the announcement.

The federal agency is seeking more support from within the government and reassigning staff as it assembles a public-private consortium to address long-term challenges and determine how to improve the NVD program. In the interim, the temporary delays in CVE analysis will result in less detailed analysis of vulnerabilities deemed non-urgent.

The work and output of NIST’s NVD program is remarkable. The agency reported an all-time high of 33,137 disclosures last year, a 318% increase from 2005 when the NVD first came online, according to Flashpoint research.

Government agencies, private companies, researchers and threat hunters use NVD’s standards-based vulnerability management data to automate security measurement and compliance, and assess, mitigate and spot potential risks lurking in these CVEs.

“So many folks have, honestly, probably been taking it for granted for years,” said Caitlin Condon, director of vulnerability research at Rapid7.

NVD has long been an authoritative and widely trusted source for vulnerability information, despite occasional disputes about NIST’s timeliness or transparency, CVSS scores, common platform enumeration (CPE), or root cause identification.

“Security professionals across a variety of disciplines like research and vulnerability management have come to rely on NVD,” said Emily Austin, principal security researcher at Censys. “It's built into vulnerability management tools and processes across many organizations, and its importance really can't be overstated.”

NVD slowdown creates difficulties downstream

Impacts from the NVD slowdown are expected to materialize over time, and cybersecurity experts anticipate a snowball effect as some vulnerabilities receive less attention from NIST.

Some vendors disclose very little information about vulnerabilities in their products. When NIST isn’t filling that analysis gap, the responsibility ultimately falls on threat hunters, researchers and security companies.

Other vulnerability catalogs exist, such as the Mitre Corp.’s CVE.org and the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities catalog, but the former doesn’t have the federal government’s official backing as a trusted source of truth and the latter is limited in scope.

“There’s value in being able to use a common language to discuss CVEs. That said, I also see concerns with having a single point of failure, as we’re experiencing now,” Austin said.

The temporary delays have already made it much more difficult for organizations to understand what software and products in their environments are vulnerable to a given CVE, according to Austin.

“Those working in vulnerability management and the tools they rely on are at a major disadvantage as a result of the NVD issues,” Austin said.

Challenges confronting the NVD

The sheer glut of vulnerabilities that NIST must analyze combined with the agency’s resource constraints has created a backlog in the NVD.

“Even before the start of the NVD slowdown, NVD has been significantly behind in analysis of the growing number of disclosures for years, often ranging from two to six weeks to analyze a given vulnerability. Over time, this gap in coverage has culminated to over 100,000 vulnerabilities missed by CVE and NVD,” Flashpoint research found.

Budget alone cannot fix NIST's constraints because people with the specialized skills required to analyze issues confronting AI, climate, communications, cybersecurity, health, infrastructure, manufacturing and quantum science are scarce. The agency has an expansive remit to promote U.S. innovation and competitiveness by advancing measurement science, standards and technology.

That kind of lofty mission requires resources.

The agency, which has a workforce of approximately 3,400 people and a fiscal year 2023 budget of $1.6 billion, is struggling to compete for and retain specialized talent in a competitive market, according to a 2023 report by the U.S. Government Accountability Office.

NIST did not answer questions about how many employees are responsible for the NVD or when it expects to complete the improvement process and return to normal operations.

A large portion of NIST’s analysis resources are spent on CPE generation, which, in theory, is work best suited for the software vendor, according to Condon.

“I would wonder whether any software vendors even know that that's their responsibility, or that they are in the best position to be doing it,” she said.

The current model isn’t working and this underscores the extent to which more entities and experts across the cybersecurity industry need to step up and rely less on NIST.

“I’m not sure what they owe us,” Condon said. “I would hope that a larger portion of our energy and brainpower and discussion goes toward understanding the process as it works today, where the pain points are, what we need it to do, and then where there are opportunities for scalability improvements.”

What’s going on with the National Vulnerability Database? (2024)
Top Articles
Rule 1028 - Preliminary Objections, 231 Pa. Code r. 1028
Reserve Bank of India - Master Circulars
Netronline Taxes
Visitor Information | Medical Center
Ixl Elmoreco.com
Rabbits Foot Osrs
Miles City Montana Craigslist
Shaniki Hernandez Cam
Wunderground Huntington Beach
Goldsboro Daily News Obituaries
Craigslist Pets Southern Md
2016 Hyundai Sonata Price, Value, Depreciation & Reviews | Kelley Blue Book
Aspen.sprout Forum
Transfer Credits Uncc
No Hard Feelings Showtimes Near Cinemark At Harlingen
Minecraft Jar Google Drive
Dutch Bros San Angelo Tx
Craftology East Peoria Il
Me Cojo A Mama Borracha
Velocity. The Revolutionary Way to Measure in Scrum
NBA 2k23 MyTEAM guide: Every Trophy Case Agenda for all 30 teams
Joann Ally Employee Portal
Amazing Lash Studio Casa Linda
R. Kelly Net Worth 2024: The King Of R&B's Rise And Fall
Certain Red Dye Nyt Crossword
The Listings Project New York
Rugged Gentleman Barber Shop Martinsburg Wv
2023 Ford Bronco Raptor for sale - Dallas, TX - craigslist
2015 Kia Soul Serpentine Belt Diagram
100 Gorgeous Princess Names: With Inspiring Meanings
Visit the UK as a Standard Visitor
Craigslistodessa
The Bold and the Beautiful
Craigslist Texas Killeen
Devotion Showtimes Near The Grand 16 - Pier Park
JD Power's top airlines in 2024, ranked - The Points Guy
6143 N Fresno St
Haley Gifts :: Stardew Valley
Cheap Motorcycles Craigslist
Austin Automotive Buda
Samantha Lyne Wikipedia
Seminary.churchofjesuschrist.org
Mountainstar Mychart Login
Paradise leaked: An analysis of offshore data leaks
Meee Ruh
Germany’s intensely private and immensely wealthy Reimann family
1Tamilmv.kids
Spn 3464 Engine Throttle Actuator 1 Control Command
Diamond Spikes Worth Aj
Where and How to Watch Sound of Freedom | Angel Studios
Itsleaa
Latest Posts
Article information

Author: Neely Ledner

Last Updated:

Views: 6699

Rating: 4.1 / 5 (62 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Neely Ledner

Birthday: 1998-06-09

Address: 443 Barrows Terrace, New Jodyberg, CO 57462-5329

Phone: +2433516856029

Job: Central Legal Facilitator

Hobby: Backpacking, Jogging, Magic, Driving, Macrame, Embroidery, Foraging

Introduction: My name is Neely Ledner, I am a bright, determined, beautiful, adventurous, adventurous, spotless, calm person who loves writing and wants to share my knowledge and understanding with you.