CVE
CVE is the global directory of publicly known security vulnerabilities where each vulnerability receives its own identifier.
Common Vulnerabilities and Exposures (CVE) is a global directory of publicly known security vulnerabilities. Each vulnerability receives its own identifier, such as CVE-2024-3400.
How it works
The CVE programme is operated by MITRE and funded by the US agency CISA. CVE numbers are assigned by so-called CVE Numbering Authorities (CNAs), such as manufacturers, security companies, and CERTs. Each CVE includes a brief description and references to vendor advisories.
Severity is usually rated with CVSS, a scale from 0 to 10. Further details are provided by sources like CISA's Known Exploited Vulnerabilities (KEV) catalogue. The Exploit Prediction Scoring System (EPSS) score indicates the probability of exploitation.
For example, a scan might find 3,000 open CVEs in an environment. The team cannot fix all of them at once. It prioritises vulnerabilities that are actively exploited and internet-accessible. This leaves 25 vulnerabilities to be closed within a week. The remainder are addressed according to a plan.
What to look out for
- The CVSS score alone is not sufficient for prioritisation. The key factor is whether a vulnerability is actively exploited.
- Consider how critical and how exposed the affected system is.
- Not every vulnerability has a CVE. Misconfigurations and vulnerabilities in custom-developed software are not listed in the directory.
- Follow vendor advisories directly. CVE entries can sometimes be published with a delay.
Relevance for the SOC
New critical CVEs often trigger threat hunting activities. The SOC searches for any signs of exploitation. It also creates new detection rules. Conversely, CVE information helps to better classify an Alert.
Switzerland and regulation
The National Cyber Security Centre (NCSC) reports on critical vulnerabilities with a connection to Switzerland. The Swiss Financial Market Supervisory Authority (FINMA) expects effective vulnerability management from financial institutions. ISO 27001 also contains a relevant control.
Typical mistakes
A common mistake is patching strictly according to the CVSS score. This can leave actively exploited, medium-risk vulnerabilities unaddressed. Another mistake is generating reports with thousands of entries that fail to produce any concrete action.
How we implement it
We offer Vulnerability Management as one of our Security Services. CVE information is also used to enrich Alerts.