The NVD and meltdown? CVE Slowdown Current uncertainties and alternative
?? Francesco ?? Cipollone
Reduce risk - focus on vulnerabilities that matter - Contextual ASPM - CEO & Founder - Phoenix security - ??♂? Runner - ?? Application Security Cloud Security | 40 under 40 | CSA UK Board | CSCP Podcast Host
The world of vulnerabilities relies on NVD, and the very foundations are shaky. If you new in the cybersecurity and vulnerability space the National Vulnerability Database (NVD) stands as a cornerstone for the standardization of vulnerabilities, developers, and software vendors alike. Established by the National Institute of Standards and Technology (NIST), the NVD provides a comprehensive catalogue of information on publicly disclosed cybersecurity vulnerabilities. This critical resource plays a pivotal role in the vulnerability management lifecycle, enriching data from the Common Vulnerabilities and Exposures (CVE) Program managed by Mitre, with additional details such as severity scores, affected products, and potential weaknesses.
Comment below what you think of the current situation and what you think could be done to improve
The Criticality of NVD and Its Current Challenges
I can't stress the pressure that the NVD has on the API and how drastic consequences any changes cause. Recently, the NVD has undergone changes in the API method of querying for vulnerabilities and, more recently, changes in the CPE declaration with the almost absence of CPE enrichment. From 2015 to 2023, we saw an increase of 33X in the number of vulnerabilities.
The NVD's importance cannot be overstated. It serves not just as a repository but as an essential tool for the identification and mitigation of vulnerabilities, offering details like Common Platform Enumerations (CPEs).
Other than CPE backlog there is a whole lot of backlog of vulnerabilities in the NVD awaiting processing. The process of getting a CVE into the NVD seems straightforward from the current description.
The reality of it is much more complex, and Patrick Garrity ?????? has done great work some time ago analysing the whole flow:
Current Situation with CPE
CPEs are vital as they inform users about the specific software and products impacted by a CVE. However, a significant challenge has emerged: the slowdown in the publication of new vulnerabilities and the enrichment of existing ones, particularly the addition of CPE information. A longer article by Kevin Poireault explores additional elements of the current situation including almost the halt of the NVD in processing and enriching information
For a deeper dive into the vulnerabilities Chris H. has also summarized this beautifully in this longer article https://resilientcyber.substack.com/p/death-knell-of-the-nvd
Dan Lorenc from the security community has pointed out a concerning trend: the apparent discontinuation by the NVD of adding CPE matches to CVEs. This change means that CVE entries are increasingly devoid of critical metadata, indicating which software is actually affected. This development is particularly troubling, as it hampers the ability of organizations to identify and prioritize vulnerabilities within their environments accurately.
On February 15, the NVD website acknowledged that users might face "delays in analysis efforts," revealing that NIST is in the process of forming a consortium aimed at addressing the NVD program's challenges and developing enhanced tools and methodologies.
领英推荐
The Escalating Demand and the Strain on Resources
The NVD's challenges are compounded by the sheer volume of vulnerabilities it processes. From a few hundred to over 2000 monthly, the number of vulnerabilities has seen an astonishing 35% year-on-year increase. This exponential growth places an immense strain on the NVD's resources, necessitating a significant expansion in capacity and capabilities to keep pace.
Jerry Gamblin monitors the number of requests in the NVD and has recently flagged a backlog of vulnerabilities in the pipeline.
Moreover, the recent transition from version 1 to version 2 of the vulnerability management framework and the implementation of API throttling have further complicated access and utilization of the NVD's services. These changes, while aimed at improving the system's efficiency and reliability, have resulted in additional hurdles for users reliant on real-time data for vulnerability management.
Navigating Through the Slowdown: Seeking Alternatives
Given the current challenges, the cybersecurity community must explore alternatives and supplementary strategies to mitigate the impact of the NVD's slowdown. Here are some considerations:
Patrick Garrity ?????? has flagged in this article https://www.dhirubhai.net/pulse/security-industry-depends-nvd-patrick-garrity--jwq9c/ as well the need to have a petition for funding
Reminder of open source and USA-founded vulnerabilities database is still open source.
some historical reasoning from Patrick Garrity ?????? on the current challenges of NVD
The Path Forward
The NVD's current predicament underscores the critical need for sustained support, investment, and innovation to address the burgeoning demands of vulnerability management. As the cybersecurity landscape continues to evolve, so too must the tools and resources we rely on to protect our digital infrastructure.
The initiative by NIST to establish a consortium offers a glimmer of hope for the future of the NVD program. However, it is incumbent upon the entire cybersecurity community to rally in support of these efforts, advocating for the resources and reforms necessary to ensure the NVD can continue to fulfill its vital role in our collective security.
How many vendors utilise the NVD feed to associate risks to assets and then claim they have vulnerability management capabilities?
?? Start-& Scale-Up Growth??Data-Driven Assessments | natural leader | driven by challenges | solution- and people-oriented | sales strategy, training, coaching | industry agnostic | 20k+ sales meetings arranged ??
8 个月Your detailed analysis sheds light on the critical challenges facing the NVD. Collaboration and action are key in addressing these issues. Keep up the great work! ??
Digital Marketer | Cyber Security Practitioner (Ce-CSP) |?CISMP |?ISO 27001 |?ITF+ | CCSK
8 个月Absolutely vital to address these challenges facing the NVD and cybersecurity infrastructure. Let's collaborate for sustainable solutions. ??
Great dad | Inspired Risk Management and Security Profesional | Cybersecurity | Leveraging Data Science & Analytics My posts and comments are my personal views and perspectives but not those of my employer
8 个月We can sympathize with the #NIST and #NVD efforts all we want. I do not see this coming back to be a reliable source to depend on with the government budget restrictions as an ax over its head. The private sector should take the flag and move it forward. Do we want to pay for a CVE list? Most likely not but most people will if an entity delivers a reliable source to help prioritize efforts.
Technology Executive | Security Engineering | Security Architecture
8 个月Satwik Banerjee - inteeesting read.