A US Commerce Department Inspector General report criticizes NIST for mismanaging the National Vulnerability Database (NVD), citing a growing backlog of unprocessed vulnerabilities, duplicated efforts with CISA's Vulnrichment program wasting ~$200K, and unreliable CVSS severity scoring where independent evaluators matched NIST scores only 12% of the time. The report estimates $800K could be better used over two years. NIST agreed with technical recommendations but disputed the report's tone. Industry experts argue the real issues are budget cuts, over-reliance on NVD as a sole vulnerability source, and the inability of manual processes to keep pace with AI-accelerated vulnerability discovery.
97 Impressions