Distributing Product Vulnerability Information: The Cisco VEXperience

Dario Sicaron (Principal Engineer · Cisco)

CVE/FIRST VulnCon 2025 · Main Stage

Overview

In an era of increasingly complex software supply chains, understanding the impact of third-party software (TPS) vulnerabilities on commercial products is a critical challenge for both vendors and customers. Dario Sicaron, a Principal Engineer with Cisco’s Security and Trust Organization, presented "Distributing Product Vulnerability Information: The Cisco VEXperience" at VulnCon, detailing Cisco's strategic initiative to provide clear, machine-readable vulnerability exploitability eXchange (VEX) information. This talk highlights Cisco's journey to centralize and standardize the distribution of vulnerability data, particularly focusing on how vulnerabilities in common open-source components like OpenSSL and OpenSSH affect Cisco's extensive product portfolio.

Watch on YouTube

Visual summary for Distributing Product Vulnerability Information: The Cisco VEXperience by Dario Sicaron
Visual summary for Distributing Product Vulnerability Information: The Cisco VEXperience by Dario Sicaron

Key moments

  1. 0:00 Speaker introduction and extensive professional background
  2. 2:11 Overview of Cisco's multiple vulnerability distribution mechanisms
  3. 2:48 Traditional Cisco Security Advisories (HTML and CSAF)
  4. 6:08 Identifying limitations of existing tools for TPS vulnerabilities
  5. 6:39 Introducing CVR: The new Cisco Vulnerability Repository
  6. 6:58 CVR's primary focus: third-party software vulnerabilities (VEX)
  7. 8:12 CVR features: VEX document download and filtering options
  8. 8:49 Visual example of the CVR user interface screenshot

Distributing Product Vulnerability Information: The Cisco VEXperience

Speakers: Dario Sicaron, Principal Engineer, Security and Trust Organization at Cisco

Conference: VulnCon

YouTube: https://www.youtube.com/watch?v=qfDMiYj6hwI

Overview

In an era of increasingly complex software supply chains, understanding the impact of third-party software (TPS) vulnerabilities on commercial products is a critical challenge for both vendors and customers. Dario Sicaron, a Principal Engineer with Cisco’s Security and Trust Organization, presented "Distributing Product Vulnerability Information: The Cisco VEXperience" at VulnCon, detailing Cisco's strategic initiative to provide clear, machine-readable vulnerability exploitability eXchange (VEX) information. This talk highlights Cisco's journey to centralize and standardize the distribution of vulnerability data, particularly focusing on how vulnerabilities in common open-source components like OpenSSL and OpenSSH affect Cisco's extensive product portfolio.

Sicaron’s presentation delves into the mechanics of the Cisco Vulnerability Repository (CVR), a platform launched in May 2022 designed to address the specific problem of TPS vulnerabilities. He shares compelling data insights derived from nearly three years of CVR usage, revealing customer priorities, common query patterns, and the nascent but growing adoption of VEX documents. The talk underscores the industry-wide push for greater transparency and automation in vulnerability management, advocating for security scanner vendors and customers to embrace VEX for more accurate and actionable vulnerability assessments.

This initiative is significant because it tackles a pervasive problem: customers often struggle to ascertain whether a publicly disclosed vulnerability in a third-party component actually impacts their specific product version. Cisco's VEXperience aims to provide definitive answers, reducing the noise of irrelevant alerts and enabling customers to focus their defensive efforts where they matter most. By moving towards machine-readable VEX and an eventual API, Cisco is not just providing data, but actively shaping the future of automated vulnerability information exchange in the enterprise ecosystem.

Background

▶ Watch: Speaker introduction and extensive professional background (0:00)

Before the advent of the CVR, Cisco, like many large technology vendors, relied on a diverse set of mechanisms to communicate vulnerability information. These included traditional Cisco Security Advisories, published in both human-readable HTML and machine-readable CSAF (Common Security Advisory Framework) formats. Additionally, Cisco offered an Open Vulnerability API for programmatic queries, a Software Checker tool limited to a subset of products, and the Bug Search Toolkit for general defect information, including some security vulnerabilities.

While these tools served their purpose, they presented several limitations, particularly concerning vulnerabilities stemming from third-party software components. The traditional advisories primarily focused on Cisco's own vulnerabilities, rarely addressing issues in third-party components unless they were exceptionally critical. The Open Vulnerability API and Software Checker were also largely restricted to Cisco-originated vulnerabilities and a limited range of Cisco operating systems and products. The Bug Search Toolkit, while comprehensive for any defect, was often cumbersome for customers trying to filter specifically for security vulnerabilities in third-party components affecting their specific product, platform, and release. This fragmented approach meant that customers frequently faced challenges in determining the precise impact of a widespread TPS vulnerability (e.g., in OpenSSL, Apache Tomcat, OpenSSH) on their diverse Cisco deployments. They would often resort to manual checks, scanning reports, or opening support tickets, leading to inefficiencies and potential misprioritization of threats.

The problem arises from the ubiquitous integration of open-source and commercial third-party components into modern software products. A single vulnerability in a widely used library can affect countless products across many vendors. Customers need a definitive "affected" or "not affected" status from their vendors, not just a list of components used. This gap necessitated a more centralized, standardized, and machine-readable approach, leading to the development of the Cisco Vulnerability Repository with its focus on VEX.

Key Findings

▶ Watch: Traditional Cisco Security Advisories (HTML and CSAF) (2:48)

The data presented by Dario Sicaron offers a fascinating glimpse into customer behavior regarding vulnerability information for third-party software components in Cisco products. The analysis is based on CVR usage data collected over nearly three years, from May 2022 to early 2025, encompassing approximately 170,000 valid query records from just under 13,000 unique users.

One striking finding is the relatively small number of unique CVE IDs queried: out of the thousands of CVEs issued since 1999, only 7,700 unique CVE IDs related to third-party software components were queried by Cisco customers. This suggests that while the overall volume of vulnerabilities is high, customers are highly selective in what they actively investigate in the context of their Cisco products.

Customer interest is highly concentrated:

  • Product Focus: Just 10 Cisco products account for 70% of all queries against the CVR. Top products include Cisco XR, Identity Services Engine, and Firepower Threat Defense, indicating a strong focus on core networking and security infrastructure. Some flagship products surprisingly garnered less interest than anticipated, while others exceeded expectations.
  • CVE Popularity: A significant portion of CVEs are rarely queried. 45% of the queried CVE IDs (approximately 3,500 CVEs) were queried only once. Conversely, a tiny fraction of CVEs drives the majority of activity: only 17 CVE IDs (less than 0.25% of the total queried) account for over 50% of all queries. This highlights a severe clustering of customer concern around a very small number of highly visible or impactful vulnerabilities.
  • CVSS Score vs. Query Volume: Contrary to a common assumption that customers primarily focus on Critical and High severity vulnerabilities, the data shows a different trend. 55% of the queried CVEs have a CVSS 3.1 base score of Medium or Low. Furthermore, more than 50% of all queries were for CVEs with a Medium or Low CVSS base score. This suggests that factors beyond the raw CVSS score, such as the perceived exploitability, the ubiquity of the affected component, or the specific context of the customer's environment, heavily influence query behavior.
  • CISA KEV Catalog Relevance: Only 413 (less than 6%) of the queried CVE IDs are present in the CISA Known Exploited Vulnerabilities (KEV) catalog. These KEV-listed CVEs represent a mere 5% of all queries, indicating that while important, the KEV catalog is not the sole or primary driver of customer inquiries for TPS vulnerabilities in Cisco products.
  • Most Queried CVEs and Components: The top 15 most queried CVEs revealed a strong bias: 13 of these were related to OpenSSH, one to the general SSH protocol (CVE-2023-48795, Terrapin attack, which was the most queried overall), and only one was for something else (ActiveMQ). This strongly suggests that customers are highly concerned about vulnerabilities in network-facing components used for product administration and management. Looking at the top 100 most queried CVEs, OpenSSH and OpenSSL together account for almost 50% of the affected TPS components. Apache Tomcat follows with 11%. Interestingly, Log4Shell (Log4j) was not a significant driver of CVR queries, likely because Cisco would have issued specific advisories for its own products affected by Log4j, which fall outside CVR's primary scope for TPS vulnerabilities. Furthermore, 10 of the top 100 most queried CVEs were actually Cisco's own CVE IDs, implying some customer confusion or a tendency to use CVR even when a dedicated Cisco advisory might exist.
  • VEX Document Download Adoption: The capability to download VEX documents was added in June 2023. By early 2025, a total of 6,589 VEX documents had been downloaded. These downloads were concentrated across 89 products (out of 252 available in CVR) and covered just over 500 unique CVE IDs (out of the 7,700 queried). The top 10 products for VEX downloads largely mirrored the top 10 for queries, with Cisco XR software remaining at the top. However, Cisco ASA software, a strong performer in queries, dropped out of the top 10 for VEX downloads. The top 10 CVEs for VEX downloads also largely aligned with the most queried CVEs, with Terrapin (CVE-2023-48795) again leading. This indicates that while VEX adoption is growing, it is still in its early stages, and customers are primarily downloading VEX for the same high-interest vulnerabilities they query.

Technical Deep Dive

▶ Watch: Introducing CVR: The new Cisco Vulnerability Repository (6:39)

The Cisco Vulnerability Repository (CVR) is the central technical solution presented, designed to streamline the distribution of vulnerability information, particularly for third-party software (TPS) components embedded within Cisco products. Launched in May 2022, CVR focuses specifically on vulnerabilities where the root cause lies in a component like OpenSSL, OpenSSH, Apache, or Tomcat, rather than Cisco's proprietary code.

The CVR's core functionality revolves around providing precise vulnerability exploitability eXchange (VEX) information. VEX is a type of CSAF document that explicitly states whether a product is "affected," "not affected," or "under investigation" by a specific vulnerability, even if the vulnerable component is present. This is crucial because the mere presence of a vulnerable component does not automatically mean the product itself is vulnerable; mitigation techniques, specific configurations, or code paths might render the product immune.

Users interact with CVR primarily through a web-based graphical user interface (GUI), although future API access is planned. The GUI supports two main query types:

  1. Narrow Query: This allows a user to specify a precise combination of a CVE ID, a Cisco product, a platform, and a software release. For example, a user might ask: "Does CVE-2023-48795 (Terrapin) affect Cisco Identity Services Engine running software release 3.2 on a specific platform?" The CVR then provides an explicit "Affected" or "Not Affected" status. If the information is not immediately available, users can initiate a "Request Assessment," which automatically opens a ticket with the relevant Cisco product development team to investigate and provide an answer. This mechanism ensures that even obscure or newly reported vulnerabilities can be addressed directly by product experts.
  1. Broad Query: For users who want a wider overview, a broad query involves entering only a CVE ID. The CVR then returns a comprehensive list of all Cisco products, platforms, and releases that are either affected or not affected by that specific CVE. This allows customers to quickly identify the scope of a vulnerability across their entire Cisco infrastructure. The results are presented hierarchically, allowing users to expand product entries to see affected platforms and then specific releases.

A critical feature of CVR, introduced in June 2023, is the VEX document download capability. For any specific product, platform, release, and CVE ID combination, users can download a CSAF document using the VEX profile. This machine-readable document provides the authoritative "affected" or "not affected" status along with any relevant details, workarounds, or fix versions. This capability is pivotal for automating vulnerability management processes, as security tools can parse these documents directly.

Looking ahead, Cisco has outlined several significant enhancements to the CVR:

  • Multi-CVE / Comprehensive VEX Download: As of January 2025, CVR supports the download of a single VEX document that contains all known TPS vulnerabilities for a selected product, platform, and release combination. This eliminates the need to download individual VEX documents for each CVE, providing a holistic view of a product's TPS vulnerability posture.
  • Migration of Traditional Advisories: Within the next six months (from the talk date), Cisco plans to migrate its traditional advisories (which cover Cisco's own vulnerabilities) into the CVR. While the advisories will not be discontinued, they will be presented within the CVR framework, offering a unified source for all Cisco vulnerability information, regardless of its origin (Cisco's code or TPS). This will also enable VEX document downloads for Cisco's own CVEs.
  • API Development: Cisco is actively developing and testing an API for CVR. This will allow customers to programmatically query the repository and download VEX documents, enabling seamless integration with enterprise vulnerability management systems, security orchestration, automation, and response (SOAR) platforms, and other security tools. The API is currently in Early Field Trial (EFT).

Authentication for CVR access requires a free guest account. This is not a paywall but a mechanism for Cisco to collect usage data and potentially tailor services, while keeping the core vulnerability information accessible to all. The CVR currently holds information for TPS vulnerabilities disclosed from 2018 onwards and does not yet support cloud offerings.

Demo / Proof of Concept

▶ Watch: CVR's primary focus: third-party software vulnerabilities (VEX) (6:58)

While the talk did not feature a live, interactive demonstration, Dario Sicaron presented several screenshots that effectively illustrate the user experience and core functionalities of the Cisco Vulnerability Repository (CVR). These screenshots served as a virtual demo, walking the audience through the process of querying for vulnerability information.

The presentation showcased how users can initiate a "narrow query" by entering a specific CVE ID and then selecting a particular Cisco product, platform, and software release. The visual examples depicted the CVR interface providing a clear status: either "is not affected" (in green) or "is affected" (prominently highlighted in red). Crucially, the screenshots also demonstrated the presence of a direct link to "download this data as a VEX document" for the specific query result.

A second set of screenshots illustrated the "broad query" functionality. Here, a user would simply enter a CVE ID without specifying product details. The CVR then returns a comprehensive, expandable list of all Cisco products, platforms, and releases that are relevant to that CVE. Users can click on plus signs to expand product entries into platforms, and then into specific releases, to see the individual determination. This visual representation highlights the tool's ability to provide a wide-ranging impact assessment across Cisco's portfolio.

Finally, the "demo" also covered the scenario where CVR does not immediately have an assessment for a particular query. A screenshot displayed a button labeled "Request Assessment." This feature acts as a proof of concept for the underlying workflow: clicking this button automatically triggers the creation of an internal ticket, routing the customer's inquiry to the appropriate Cisco product development team for investigation. Once the team provides an assessment, that information can then be communicated back to the customer and updated in the CVR.

These visual aids effectively conveyed the CVR's user-friendly interface for both targeted and broad vulnerability lookups, the clarity of its affected/not affected status, and the crucial VEX download capability, providing a tangible understanding of how customers interact with the platform.

Defensive Implications

▶ Watch: Visual example of the CVR user interface screenshot (8:49)

The Cisco VEXperience and the underlying Cisco Vulnerability Repository offer several critical implications for defenders seeking to enhance their vulnerability management strategies:

  1. Prioritize Beyond Raw CVSS Scores: The data clearly indicates that customers are not solely driven by high CVSS base scores. Over 50% of queries were for medium or low severity CVEs, and the most queried components were ubiquitous network-facing services like OpenSSH and OpenSSL. Defenders should adopt a more nuanced risk assessment model that considers not only technical severity but also component ubiquity, exploitability context (e.g., network accessibility), and the specific operational impact to their environment. This means moving beyond simple scanner outputs and leveraging vendor-provided VEX data for context.
  1. Embrace Machine-Readable VEX: The long-term vision is for VEX (Vulnerability Exploitability eXchange) to become the standard for conveying vulnerability status. Defenders should actively explore and implement tools and workflows capable of consuming and parsing CSAF VEX documents. This transition from human-readable advisories to machine-readable data is crucial for automating vulnerability assessment, reducing manual effort, and scaling security operations. Cisco's multi-CVE VEX download and upcoming API are designed to facilitate this automation.
  1. Demand VEX Consumption from Security Scanner Vendors: A major pain point highlighted is the discrepancy between scanner reports and actual product vulnerability. Scanners often flag vulnerable components without understanding the product's mitigations. Defenders should actively pressure their security scanner vendors to integrate SBOM (Software Bill of Materials) and VEX consumption into their products. By doing so, scanners can provide far more accurate assessments, eliminating "ghost vulnerabilities" and allowing defenders to focus on real threats, thereby significantly improving the signal-to-noise ratio in vulnerability reports.
  1. Leverage CVR for Authoritative Cisco Product Information: Cisco customers should make the CVR their primary source for determining the impact of third-party software vulnerabilities on their Cisco products. Utilizing the "narrow query" for specific product/version assessments and the "broad query" for comprehensive impact analysis can provide definitive answers, reducing reliance on generic scanner output or time-consuming manual investigations. The "Request Assessment" feature provides a direct channel for obtaining clarity when data is not immediately available.
  1. Prepare for API-Driven Automation: With Cisco's planned CVR API, defenders can look forward to programmatically integrating vulnerability status checks directly into their existing vulnerability management platforms, CI/CD pipelines, or SOAR playbooks. This will enable near real-time, automated assessment of their Cisco asset inventory against new TPS vulnerabilities, significantly improving response times and operational efficiency.
  1. Utilize Comprehensive VEX Downloads: The recent addition of multi-CVE VEX downloads allows defenders to get a complete vulnerability posture for a specific Cisco product, platform, and release in a single machine-readable document. This is invaluable for inventory management, compliance reporting, and creating a baseline security posture.

By actively engaging with CVR, adopting VEX, and pushing for ecosystem-wide VEX integration, defenders can move towards a more proactive, accurate, and automated approach to managing vulnerabilities in their complex environments.

Key Takeaways

  • Cisco Vulnerability Repository (CVR) Centralizes TPS Vulnerability Data: Launched in May 2022, CVR is Cisco's dedicated platform for providing definitive "affected" or "not affected" status for vulnerabilities in third-party software components (e.g., OpenSSL, OpenSSH) impacting Cisco products.
  • Customer Focus Concentrated on Few Products and CVEs: CVR data shows that 10 Cisco products account for 70% of queries, and a mere 17 CVEs drive over 50% of all inquiries. Customer concern is heavily clustered around common, network-facing components like OpenSSH and OpenSSL, which dominate the most queried CVEs.
  • CVSS Base Score Not the Sole Driver of Customer Concern: Over 50% of CVR queries are for vulnerabilities with Medium or Low CVSS 3.1 base scores, suggesting that factors like component ubiquity, perceived exploitability, and operational context often outweigh raw severity in driving customer investigations.
  • VEX Adoption is Nascent but Growing, with Challenges: While CVR offers machine-readable VEX downloads, adoption is still low (~6,600 downloads over ~1.5 years), indicating that many customers and their tools are not yet equipped to consume VEX, often still preferring traditional formats like Excel spreadsheets.
  • Cisco is Investing in Comprehensive, Automated VEX Delivery: Future CVR enhancements include multi-CVE VEX downloads (already implemented), migration of Cisco's own advisories into CVR within six months, and the development of an API for programmatic access, aiming for a unified, machine-readable vulnerability information ecosystem.
  • Call to Action for Security Scanner Vendors and Customers: Cisco urges security scanner vendors to consume SBOM and VEX data directly from vendors like Cisco to provide more accurate vulnerability reports, reduce "ghost" vulnerabilities, and improve customer experience. Customers are encouraged to demand this capability from their scanner providers.

About the Speaker(s)

Dario Sicaron is a Principal Engineer within the Security and Trust Organization at Cisco. He brings a wealth of experience to the field of cybersecurity, having spent 20 years with Cisco's Product Security Incident Response Team (PSIRT), where he witnessed and responded to numerous security incidents that he describes as profoundly impactful.

Prior to his extensive tenure at Cisco, Dario was involved in various security practices, including penetration testing (what he referred to as "white hat hacking" back in the day) and the design and implementation of security solutions. His background also includes government work, where he managed networks running legacy systems such as Novell NetWare 3.11, 3.51, and SCO Unix 3, providing a deep historical perspective on network infrastructure.

Sicaron's early career showcased a strong foundational interest in computing and security; he learned to program in Pascal at university and, in high school, was disassembling computer viruses like Jerusalem M1808 using the DOS debug utility from the command line. This diverse experience, spanning from foundational network management to modern vulnerability response and the future of VEX, highlights his deep understanding of the evolving cybersecurity landscape.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent, practitioner-focused case study from Cisco's PSIRT-adjacent engineering team on building and operating a centralized TPS vulnerability repository with VEX output. The real value here is the empirical usage data — query distributions, CVE clustering, CVSS-vs-behavior gaps — which is genuinely useful signal for anyone building or consuming vulnerability tooling. This isn't research, it's an operational retrospective, and judged on that lane it delivers adequately. It won't set the conference on fire, but it's honest about what it is, and the data is more interesting than the tooling itself.

Heather Calloway (CISO) — SOLID

A credible, data-grounded practitioner talk from someone who clearly owns this problem at Cisco. Sicaron presents real usage data from CVR and makes a coherent case for VEX adoption. The governance implication — that the industry needs machine-readable, vendor-authoritative vulnerability status to replace scanner noise — is real and worth hearing. But the talk stays inside Cisco's walls. It describes a vendor's internal journey and product roadmap more than it equips security leaders to make institutional decisions. Useful reference material for vulnerability management practitioners; not a must-see for CISOs.

→ Top-rated talks at CVE/FIRST VulnCon 2025

All talks from CVE/FIRST VulnCon 2025