Cyberfunk 📟

NIST…NIST…NIST

NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions

A couple of critical changes from NIST on how we challenge CVE’s in our infrastructure.

Any CVE submission that doesn't meet these thresholds will be marked as "Not Scheduled." The idea, NIST said, is to focus on CVEs that have the maximum potential for widespread impact.

The thresholds are below:

Changes in NVD:

My question is would this shared responsibility to CVE prioritization fall upon the vendor? What is the future of CVE scoring? Will this affect EPSS? Will this change legacy workflows?

With budget and layoffs happening throughout our governement (very gross by this administration btw) its affecting how infrastructure protects themselves.

It seems that CISO’s will now have to prioritize what vulnerabilities they deem important to the organization.

On the plus side this allows to organizations to prioritize realistic vs theoretical. Allowing for a more aggressive and accurate approach to critical findings in their infrastructure. Also opening doors to new data sets, and researchers to tackle the remaining CVE’s without a score.

Heres a couple of screenshots from a Vulnerability Analyst at NIST.

IMG_0793

IMG_0794