NIST's April 2024 decision to scale back CVE enrichment in the National Vulnerability Database (NVD) is producing measurable negative effects, according to two months of data analyzed by cybersecurity startup Volerion. Of 13,441 non-rejected CVEs published between April 15 and June 15, over 1,500 prioritized for enrichment remain unanalyzed. Timeliness is also a concern, with bottlenecks emerging during high-volume weeks. Beyond coverage gaps, accuracy is a significant problem: NIST's own CVSS scores frequently disagree with vendor and third-party assessments, particularly around attack complexity ratings. Without independent NIST scores, organizations must rely on CNA-provided scores that can be biased — vendors may deflate scores for their own products while security firms may inflate them. Volerion recommends organizations build their own vulnerability prioritization decision trees rather than relying solely on CVSS scores, and notes it is assisting CISA with its Vulnrichment project as an alternative enrichment source.

8m read timeFrom darkreading.com
Post cover image
Table of contents
CVE Coverage Gaps, DelaysCVE Inaccuracies, Score DiscrepanciesNIST Hampered by CVE Volume, Data Issues
101 Impressions