ended4월 18일· 1 sources

NIST Abandons Comprehensive CVE Enrichment, Focuses on Critical Vulnerabilities

NIST의 CVE 정책 전환: 전수 보강 중단, 중요 취약점 집중

Why it matters

NIST's decision to stop enriching most CVEs signals a fundamental shift in how vulnerability data is managed globally. With tens of thousands of new CVEs reported annually and limited resources, the agency has concluded that attempting comprehensive enrichment is futile. This move will force vulnerability management companies to independently enrich non-critical vulnerability data, marking a significant transition away from a centralized source of truth.

1
Sources
+0
24h
Growth
156d
Active
CVE enrichmentvulnerability databaseCISA KEVmetadatacritical softwarevulnerability management

Sources

Related Issues