CISA’s North Star Vision for the CVE Program

CVE/FIRST VulnCon 2025 · Main Stage

Overview

This panel discussion, held at VulnCon, delves into the past, present, and future of the CVE (Common Vulnerabilities and Exposures) program, celebrating its 25-year milestone while charting CISA's "North Star" vision for its evolution. Moderated by Sandy Radesky of CISA's vulnerability management team, the panel brings together representatives from CISA, MITRE, and the commercial security sector to discuss the critical importance of vulnerability data in cyber defense. The core of the conversation revolves around the program's transition from a phase of rapid growth and adoption to a new era focused intently on data quality and completeness.

Watch on YouTube

Visual summary for CISA’s North Star Vision for the CVE Program
Visual summary for CISA’s North Star Vision for the CVE Program

Key moments

  1. 0:00 CISA's introduction, 25-year CVE celebration, and quality focus.
  2. 2:00 CVE's rapid growth and transition to a 'quality era'.
  3. 4:00 Detailed focus on improving CVE record and process quality.
  4. 5:00 Expanding CVE coverage to underrepresented domains and open source.
  5. 6:00 Secure by Design principles and targeted partnership engagements.
  6. 7:00 Bob's holistic view of the CVE ecosystem and actual customers.

CISA’s North Star Vision for the CVE Program

Speakers: Sandy Radesky (CISA, Moderator), Alec Summers (MITRE), Bob Lord (CISA), Ben Edwards (Commercial Security Analyst)

Conference: VulnCon

YouTube: https://www.youtube.com/watch?v=X58iSkPJnUk

Overview

This panel discussion, held at VulnCon, delves into the past, present, and future of the CVE (Common Vulnerabilities and Exposures) program, celebrating its 25-year milestone while charting CISA's "North Star" vision for its evolution. Moderated by Sandy Radesky of CISA's vulnerability management team, the panel brings together representatives from CISA, MITRE, and the commercial security sector to discuss the critical importance of vulnerability data in cyber defense. The core of the conversation revolves around the program's transition from a phase of rapid growth and adoption to a new era focused intently on data quality and completeness.

The talk emphasizes that while the CVE program has achieved remarkable success in providing a universal identifier for vulnerabilities, the increasing volume of software and associated defects necessitates a strategic shift. The speakers articulate a vision where the CVE database not only serves as a comprehensive catalog but also as a foundation for proactive security measures, particularly through CISA's Secure by Design initiative. This vision aims to empower defenders with richer, more actionable intelligence while encouraging software producers to address fundamental weaknesses upstream, ultimately reducing the overall attack surface.

The panel highlights the collaborative nature of the CVE program, underscoring that its continued success hinges on active participation and feedback from the global community of CVE Numbering Authorities (CNAs), security researchers, vendors, and end-users. It's a call to action for collective innovation in addressing persistent software weaknesses and building a more resilient cybersecurity ecosystem, moving beyond mere reactive patching to a future where software is inherently more secure.

Background

▶ Watch: CISA's introduction, 25-year CVE celebration, and quality focus. (0:00)

The CVE program, celebrating its 25th anniversary, has grown into an indispensable global standard for identifying and cataloging cybersecurity vulnerabilities. From its inception, the program aimed to provide a common lexicon, enabling disparate organizations to communicate effectively about security flaws. Alec Summers of MITRE notes that the program's longevity and enduring impact are "remarkable," standing out in the rapidly evolving cybersecurity landscape. In recent years, the CVE program has experienced a rapid growth phase, marked by a significant increase in the number of participating CNAs and, consequently, a greater visibility into the sheer volume of vulnerabilities in the software ecosystem.

This growth, while positive for visibility, has simultaneously presented challenges regarding the consistency and depth of information provided within each CVE record. The panel acknowledges that the program must evolve beyond simply assigning identifiers to ensuring the data associated with those identifiers is comprehensive, accurate, and actionable. Bob Lord, co-lead of CISA's Secure by Design initiative, frames this challenge by highlighting the persistent nature of certain "unforgivable vulnerabilities." He references a 2007 MITRE paper titled "Unforgivable Vulnerabilities," which listed common, critical weaknesses like SQL injection, buffer overflows, and hardcoded credentials. Lord points out that the CWE (Common Weakness Enumeration) list from 2024 still includes many of these same issues, indicating a systemic failure in the software industry to eliminate recurring classes of defects.

The underlying problem, as discussed, is that while tools and processes for dealing with unsafe software have improved, they haven't solved the core issue. Organizations often struggle to prioritize patching ("you can't patch all the things") and are overwhelmed by the volume of new vulnerabilities. This context sets the stage for CISA's North Star vision: a deliberate shift from simply increasing the quantity of CVEs to significantly improving their quality and completeness, thereby enabling a move towards secure by design principles that address vulnerabilities at their root cause rather than merely reacting to their discovery.

Key Findings

▶ Watch: Detailed focus on improving CVE record and process quality. (4:00)

The panel discussion reveals several key findings and strategic shifts driving the future of the CVE program:

  1. Transition to a "Quality Era": The CVE program is consciously moving from a "growth era" focused on expanding coverage and the number of CNAs to a "quality era" where the emphasis is on improving the data quality of individual CVE records and the processes surrounding them. This involves considering stricter requirements for data elements and enhancing automation capabilities for CNAs.
  2. Projected Exponential Growth of CVEs: Ben Edwards presents an analysis projecting the CVE database to grow to approximately 330,000 records by 2025. While this volume might seem overwhelming, the panel views it positively as a reflection of increased visibility into the "software eating the world" phenomenon and the necessity for a common identifier to communicate effectively about vulnerabilities.
  3. Significant Improvement in CNA Data Completeness: Data presented by Ben Edwards demonstrates a substantial increase in the completeness of CVE records provided directly by CNAs. As of early 2024, 90% of CVEs include product and vendor information, and approximately 85% now include CWE and CVSS information. This trend indicates a community-wide effort to enrich records beyond the basic required fields, driven by the understanding of downstream user needs.
  4. Persistence of "Unforgivable Vulnerabilities": Despite decades of security awareness and development, fundamental weaknesses continue to dominate the vulnerability landscape. Bob Lord highlights that CWE-79 (Improper Neutralization of Input During Web Page Generation, commonly known as Cross-Site Scripting) remains the most frequently cited CWE, illustrating the industry's ongoing struggle with recurring classes of defects first identified in 2007.
  5. Intentional Federation and Partnerships: CISA's North Star vision includes intentional scaling of the CVE program, focusing on bringing in underrepresented domains (e.g., medical devices, automotive) and strengthening engagement with the open-source community. This also involves working with commercial software manufacturers to encourage them to become CNAs and take greater ownership of their products' security outcomes, aligning with Secure by Design principles.

Technical Deep Dive

▶ Watch: Expanding CVE coverage to underrepresented domains and open source. (5:00)

The technical underpinnings of CISA’s North Star vision for the CVE program revolve around enhancing the structure, content, and utility of vulnerability information. At its core, the CVE program provides a standardized identifier for publicly known cybersecurity vulnerabilities. However, the panel emphasizes that the identifier itself is only the first step; the true value lies in the metadata associated with each CVE record.

A critical component of this vision is the concept of data completeness versus data quality. Ben Edwards illustrates that while historically only three fields were strictly required (description, references, and an array of affected products/versions), CNAs are increasingly providing additional, non-mandatory information. This includes details like CWE (Common Weakness Enumeration) and CVSS (Common Vulnerability Scoring System) scores. The increase to 90% completeness for product/vendor information and 85% for CWE/CVSS directly from CNAs is a testament to the community's response to the demand for richer data. The panel notes a positive decline in the use of "other problem types" as a proxy for CWE, signaling a shift towards more structured and universally accepted weakness categorization.

Bob Lord elaborates on the distinction between "malnourished" and "enriched" CVE records. A malnourished record lacks fundamental information (e.g., product, manufacturer) that should be present from the outset. Enrichment, in his view, refers to adding information that a CNA might not have direct visibility into, such as whether a CVE is being actively exploited, details on attacker TTPs (Tactics, Techniques, and Procedures), or deeper operational context. This enrichment often comes from other agencies or commercial entities that possess broader threat intelligence. CISA, as an operational agency, actively contributes to this by providing SSVC (Stakeholder-Specific Vulnerability Categorization) scoring and maintaining the Kev (Known Exploited Vulnerabilities) catalog, which adds crucial real-world context to CVE records.

The discussion frequently returns to CWE as a pivotal element for achieving secure by design. Alec Summers clarifies the intentional and often "arcane" language of CWE, explaining that terms like CWE-79 (Improper Neutralization of Input During Web Page Generation) are defined from a weakness perspective within a vulnerability theory framework, distinct from attacker-centric terms like "Cross-Site Scripting." This precision is crucial for root cause analysis and identifying recurring classes of defects that can be eliminated upstream. The goal is to move beyond simply describing the attack (e.g., "cross-site scripting") to understanding the underlying coding error that made it possible. The panel suggests that making it "easier" for CNAs to provide granular CWE data, potentially through new technology advancements and tools like Vulnogram (a CVE record generating client), is key to improving this aspect of data quality.

Furthermore, the concept of federation is evolving. While historically focused on simply increasing the number of CNAs, intentional federation now means growing the program by targeting underrepresented domains (e.g., medical devices, automotive, open source) and evolving the roles of CNAs, roots, and CNA LRs (Last Resort). The aim is to create a more resilient and comprehensive program structure that can better serve downstream users by enabling more efficient and accurate vulnerability response. The emphasis on machine readability and ensuring data is correct, accurate, and timely is highlighted as essential for coping with the projected volume of CVEs, as human analysis alone will not suffice.

Demo / Proof of Concept

▶ Watch: Secure by Design principles and targeted partnership engagements. (6:00)

This session was a panel discussion focused on strategic vision, program evolution, and data analysis, rather than a technical demonstration or proof of concept. The speakers presented data visualizations and discussed conceptual frameworks, but no live software, tools, or exploit demonstrations were performed.

Defensive Implications

▶ Watch: Bob's holistic view of the CVE ecosystem and actual customers. (7:00)

The CISA North Star vision for the CVE program carries significant implications for cyber defenders, aiming to transform how organizations identify, prioritize, and mitigate vulnerabilities. The central theme is to equip defenders with higher-quality, more complete, and actionable vulnerability data, moving beyond basic identifiers to rich contextual information.

Firstly, the push for data completeness, particularly the inclusion of CWE and CVSS information directly from CNAs, empowers defenders to make more informed tactical decisions. With 85% of CVEs now including CWE and CVSS, security teams can leverage this data to better understand the nature and severity of vulnerabilities. CVSS scores provide a standardized measure of severity, aiding in initial prioritization, while CWE offers insights into the underlying weakness. This enables defenders to perform more effective root cause analysis within their own environments, identifying systemic issues in their software supply chain or development practices that might be contributing to a proliferation of certain weakness types (e.g., CWE-79).

Secondly, CISA's commitment to data enrichment—adding operational context like active exploitation status—is invaluable. By integrating information from the Kev (Known Exploited Vulnerabilities) catalog and applying SSVC (Stakeholder-Specific Vulnerability Categorization), CISA provides critical signals that help defenders prioritize patching efforts. As Bob Lord notes, "you can't patch all the things," so knowing which vulnerabilities are actively being exploited in the wild allows organizations to focus their limited resources on the most immediate and dangerous threats. SSVC further refines this by providing a decision tree framework that helps organizations tailor their response based on their specific risk appetite and operational context.

Thirdly, the emphasis on intentional federation and bringing more software publishers, including commercial vendors, into the CNA program has a direct benefit for defenders. When vendors become CNAs for their own products, they become the authoritative source for vulnerability information. This means defenders receive more accurate, timely, and complete data directly from the source, reducing ambiguity and accelerating response times. It also aligns with the Secure by Design principle that software manufacturers should take ownership of their customers' security outcomes, providing better data and making it easier for defenders to secure their environments rather than simply providing a "hardening guide" and wishing them luck.

Finally, the broader vision of using CVE data to identify and eliminate recurring classes of defect has long-term strategic implications. By analyzing trends in CWE data, defenders can advocate for upstream changes in software development practices, influencing procurement decisions and encouraging the adoption of more secure coding standards, frameworks, and languages (e.g., "writing everything in Rust" to mitigate buffer overflows). This shifts the defensive posture from purely reactive mitigation to proactive risk reduction, aiming to reduce the overall volume of vulnerabilities that defenders face in the first place. The panel calls for community innovation in finding ways to incorporate the "habits and instincts" of safety-focused industries (automotive, aviation) into software development to achieve this goal.

Key Takeaways

  • Shift to Quality and Completeness: The CVE program is actively transitioning from a focus on sheer growth and coverage to an era prioritizing the quality and completeness of vulnerability data within each record.
  • Growing Data Enrichment by CNAs: CNAs are increasingly providing rich metadata beyond basic requirements, with 90% of CVEs now including product/vendor info and 85% including CWE and CVSS scores, significantly aiding downstream users.
  • Persistent "Unforgivable Vulnerabilities": Fundamental weaknesses like CWE-79 (Cross-Site Scripting) continue to be prevalent, highlighting the need for the industry to address root causes and move towards "secure by design" principles.
  • Intentional Program Federation: The CVE program's growth is becoming more strategic, focusing on engaging underrepresented sectors (e.g., medical, automotive) and strengthening collaboration with commercial vendors and the open-source community.
  • Actionable Data for Defenders: CISA contributes operational value through SSVC and the Kev catalog, providing critical context (e.g., active exploitation) to help defenders prioritize and make better tactical and strategic decisions.
  • Community-Driven Improvement: The success of CISA's North Star vision relies heavily on community feedback, participation, and innovation to collectively raise the bar for data quality and work towards eliminating entire classes of recurring defects.

About the Speaker(s)

Sandy Radesky (CISA, Moderator): As a member of CISA’s vulnerability management team, Sandy moderated the panel, drawing on her past experience as a cyber defender. She emphasized CISA's role in promoting data quality and completeness within the CVE program and fostering community collaboration.

Alec Summers (MITRE): Representing MITRE, the long-standing operator of the CVE program, Alec provided historical context, highlighting the program's 25-year enduring impact. He discussed the evolution from a growth phase to a quality era and the importance of intentional federation and evolving CNA roles.

Bob Lord (CISA): As a co-lead of CISA's Secure by Design initiative, Bob focused on the upstream challenges of software security. He advocated for a customer-centric approach, emphasizing the need for commercial companies to take ownership of their customers' security outcomes and for the industry to eliminate recurring classes of defects like those identified in the "Unforgivable Vulnerabilities" paper.

Ben Edwards (Commercial Security Analyst): Ben provided a commercial vendor's perspective, presenting data analysis on CVE growth and completeness. He underscored the critical importance of CVE IDs for communication and visibility in an increasingly software-dependent world, expressing gratitude for the CVE program's ability to help vendors and customers understand and react to new vulnerabilities.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent policy/program panel from credible speakers who actually run the CVE program, celebrating a 25-year milestone and laying out CISA's 'North Star' quality-over-quantity agenda. The data points — 90% CNA completeness on product/vendor fields, 85% on CWE/CVSS, the 330K projected record count — give the talk some empirical spine, and Bob Lord's invocation of the 2007 'Unforgivable Vulnerabilities' paper to indict the industry's stagnation is the most pointed moment. But the overall content stays squarely in the 'things you could have read in a CISA blog post' zone. There's no surprise disclosure, no concrete timeline or budget commitment, no controversial position taken, and the…

Heather Calloway (CISO) — SOLID

A credible, institutionally grounded panel that marks the CVE program's 25th anniversary by articulating CISA's shift from volume to quality — enriched records, CWE completeness, SSVC integration, and intentional federation into underrepresented sectors. The data points are real and the directional argument is sound. But this is program stewardship content, not strategic leadership content. It tells defenders that better data is coming; it does not tell security leaders what to do with the data they have now, how to structure governance around vulnerability prioritization, or what accountability gaps persist inside their own organizations. Solid for a practitioner audience at a…

→ Top-rated talks at CVE/FIRST VulnCon 2025

All talks from CVE/FIRST VulnCon 2025