CVEIDs and How To Get Them
CVEIDs and How To Get Them
and Exposures
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.
Agenda
§ CVE Overview
§ How to Get CVE IDs
§ Getting your CVE ID published
§ Updating CVE IDs and Working with CVE
§ Questions and Wrap-up
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.
CVE Description, Purpose, and Value
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.
What CVE Is and Is Not
CVE is…
§ The de facto standard for uniquely identifying vulnerabilities
§ A dictionary of publicly known cybersecurity vulnerabilities
§ A pivot point between vulnerability scanners, vendor patch information,
patch managers, and network/cyber operations
CVE is not…
§ A vulnerability mitigation
– CVE IDs uniquely define vulnerabilities so that mitigations can be efficiently applied
§ A vulnerability database
– CVE allows vulnerability databases to be linked together under commonly used IDs
§ A source for vulnerability risk, impact, fix, or technical information
– Each CVE contains a unique ID, description, and references
§ A tool for publicly disclosing vulnerabilities
– CVE uses publicly disclosed vulnerability information as its source of information
|3|
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.
Who Can Assign CVE IDs?
|4|
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.
When Can You Request a CVE ID?
|5|
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.
Counting
|6|
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.
Counting Process Summary
Determine Number of Vulnerabilities
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.
Counting Process Summary
Should a CVE ID Be Assigned?
| 12 |
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.
How to Write a Description
§ If you don’t already have a style that works for CVE entries, you can
borrow MITRE’s template format
– [VULNTYPE] in [COMPONENT] in [VENDOR][PRODUCT] [VERSION]
allows [ATTACKER] to [IMPACT] via [VECTOR].
– [COMPONENT] in [VENDOR] [PRODUCT] [VERSION] [ROOT CAUSE],
which allows [ATTACKER] to [IMPACT] via [VECTOR].
§ For more information on MITRE’s style see our GitHub site
– http://cveproject.github.io/docs/content/key-details-phrasing.pdf
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.
Updating Existing CVE IDs
| 15 |
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.
A Word on Credit and Attribution
§ The CVE List does not include credit or attribution for who
discovered or contributed to the discovery of the vulnerability
as part of the information it provides
| 16 |
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.
It Takes a Community
| 17 |
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.
Resources
§ CVE Website
– http://cve.mitre.org/
§ CNA rules (if you would like to understand the rules)
– http://cve.mitre.org/cve/cna/CNA_Rules_v1.1.pdf
§ CVE Webform
– https://cveform.mitre.org/
§ CVE ID Request Guidelines
– http://cve.mitre.org/cve/researcher_reservation_guidelines
§ CVE Phrasing Documentation.
– http://cveproject.github.io/docs/content/key-details-phrasing.pdf
| 18 |
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.
Questions?
| 19 |
CVE is sponsored by US-CERT in the office of Cybersecurity and Communications at the U.S.
Department of Homeland Security. Copyright © 1999–2017, The MITRE Corporation. CVE and the
CVE logo are registered trademarks and CVE-Compatible is a trademark of The MITRE Corporation.