NIST Enrichment Reductions Impact CVE Coverage, Accuracy
This article reports on a reduction in in-depth analysis of vulnerabilities by the National Institute of Standards and Technology (NIST), impacting the National Vulnerability Database (NVD). Research by Volerion revealed significant gaps in CVE coverage and analysis, with over half of identified vulnerabilities not receiving NIST enrichment. Furthermore, the delays and inaccuracies in the enrichment process, combined with the potential for biased CVSS scores from third-party sources, pose challenges for organizations seeking to prioritize and remediate vulnerabilities effectively.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
