灰指甲用什么药最有效| 什么是幽门螺杆菌| 黑蝴蝶代表什么| eric是什么意思| 秦皇岛是什么海| 看指甲去医院挂什么科| 咳嗽白痰是什么原因| 雨污分流什么意思| 介入科主要看什么病| 蝙蝠吃什么食物| 耐药菌感染什么意思| 长生是什么意思| 语文是什么意思| 木代表什么生肖| 揭榜是什么意思| 白马怕青牛是什么意思| 番外是什么意思| 骨灰盒什么材质的好| 女生为什么会长胡子| 酷的意思是什么| 保鲜袋什么材质好| 什么是民间故事| 如火如荼什么意思| 骨折的人吃什么恢复快| 北京中秋节有什么活动| 肺气肿是什么原因引起的| 农历六月十七是什么日子| 黑裙子配什么鞋子| 树脂材料是什么| 梦见狐狸是什么预兆| 什么是电解水| 经常流鼻血是什么情况| 中将相当于什么级别| 青海湖里面有什么鱼| 痛风能吃什么菜| 椭圆形脸适合什么发型| 精神病吃什么药最好| 双鱼座上升星座是什么| 卑微是什么意思| 酒吧营销是做什么的| 肛门不舒服是什么原因| 心脏疼痛挂什么科| 猴和什么属相相冲相克| 什么水果含铁量最高| 789是什么意思| bmr是什么意思| 一月15号是什么星座| 医学上pi是什么意思| 女人吃什么疏肝理气| 失眠可以吃什么药| 宫颈糜烂吃什么药| 26岁属什么的生肖| 正月初十是什么星座| 多宝鱼是什么鱼| 单脐动脉对胎儿有什么影响| 沦丧是什么意思| 中性粒细胞低吃什么药| a货翡翠是什么意思| 沙发是什么头发| 为什么会得皮炎| 世界上最长的单词是什么| 圣旨是什么意思| 慢生活是什么意思| 众什么意思| 不堪一击是什么意思| 男人肝火旺吃什么药| 西安有什么特色美食| 尼哥是什么意思| 毛主席什么时候死的| 五月二十号是什么星座| 贡菜是什么菜| 黄芪泡水喝有什么功效| 莲雾什么味道| 马英九属什么| 早餐吃什么最减肥瘦身| 山穷水尽疑无路是什么生肖| 咳嗽完想吐是什么原因| o型血的人是什么性格| 慢性萎缩性胃炎吃什么药| 卫戍部队是什么意思| 加湿器什么季节用最好| 老虎下山下一句是什么| 中巴友谊为什么这么好| 效果图是什么意思| 有氧运动和无氧运动有什么区别| 庄周梦蝶什么意思| 什么多么什么造句| 腹胀做什么检查效果好| clarks是什么牌子| 什么辣椒最辣| 黑洞长什么样| 民政局是干什么的| 探索是什么意思| 为什么不能叫醒梦游的人| 夏威夷果吃了有什么好处| 坐南朝北是什么意思| 母亲节要送什么礼物| 缺钾什么症状| 1958年属什么| 什么是烟雾病| 词牌名什么意思| 十月二十二什么星座| 骨感是什么意思| 地中海贫血有什么影响| 五道杠是什么牌子| 什么是黄油| 心肌病吃什么药| 东莞有什么好玩的| 小二是什么意思| 碧玺是什么| 满月脸水牛背是什么病| 四叶草代表什么意思| 60年属鼠是什么命| 11点是什么时辰| 脾肾阳虚是什么意思| 东北属于什么气候| 喝藿香正气水不能吃什么| 脂肪瘤吃什么药可以消除| 人为什么会焦虑| 什么样的枫叶| 保家卫国是什么生肖| 吊客是什么意思| mm代表什么| manu是什么意思| 谈恋爱是为了什么| 脂肪肝什么意思| 十一月二十六是什么星座| 男生小肚子疼是什么原因| 蜘蛛的血液是什么颜色| 血浓度高是什么原因| 今年十八岁属什么生肖| 军统是什么| 一个小时尿一次是什么原因| 什么水果通便| 祸祸是什么意思| 胆囊炎吃什么药| 前位子宫和后位子宫有什么区别| 中药和中成药有什么区别| ddg是什么意思| 咳嗽吃什么| 射精什么感觉| 三月十八是什么星座| 颈动脉斑块做什么检查| 夏天穿什么鞋| 肾气不固吃什么中成药| 陈赫火锅店叫什么名字| 送人梳子的寓意是什么| 肾虚是什么原因引起的| 芊芊学子什么意思| 周杰伦英文名叫什么| 大姨妈一直不干净是什么原因| 申时是什么时间| 三线炎有什么症状| 城市户口和农村户口有什么区别| rp是什么意思| 长期喝苦荞茶有什么好处| 赞字五行属什么| 瞩目是什么意思| 打嗝吃什么药| 挚友是指什么的朋友| 什么时辰出生的人命好| 女生喜欢什么姿势| hrv是什么意思| 环比增长什么意思| 晚上尿多什么原因| 自求多福什么意思| 冰柜什么牌子好| 龙脉是什么意思| 胃一阵一阵的疼是什么原因| 野趣是什么意思| 道家思想的核心是什么| 感性的人是什么意思| 惊醒是什么意思| 射的快吃什么药| loa胎位是什么意思| 为什么海水是咸的| 莲蓬是什么| 阴茎疼是什么原因| 咸鱼翻身是什么意思| p53阳性是什么意思| 吃完芒果后不能吃什么食物| 八月生日什么星座| 吃什么东西可以减肥| 后背凉凉的是什么原因| 肝叶钙化灶是什么意思| 陕西有什么烟| evisu是什么牌子| 常青藤是什么意思| 淀粉酶高有什么危害| 低血压吃什么食物| 手信是什么意思| 吃什么能去湿气| 晚上9点到11点是什么时辰| 肩胛骨缝疼挂什么科| 贵州有什么美食| 三伏贴什么时候贴最好| 口腔义齿是什么| 眉毛白是什么原因引起的| 什么病会传染| 梦见蛇是什么意思啊| 夜盲吃什么维生素| 左腹部是什么器官| ab型血为什么容易得精神病| 固体饮料是什么意思| 脯氨酸氨基肽酶阳性是什么意思| 血沉高是什么病| 黄体酮低吃什么补得快| 喝椰子水有什么好处| 生理是什么意思| 弹性工作制是什么意思| 三高不能吃什么食物| 酸奶什么时候喝好| 寿眉属于什么茶| 琉璃是什么材料| 户籍地址填什么| 打疫苗前后要注意什么| 脸部麻木是什么的前兆| 晓五行属性是什么| 治妇科炎症用什么药好| 喉咙干是什么原因| 键盘侠是什么意思| 一语惊醒梦中人是什么意思| 害怕的近义词是什么| 为什么飞机撞鸟会坠机| 跳蚤长什么样子图片| 什么原因导致流鼻血| 头部神经痛吃什么药好| 猫代表什么象征意义| 怀不上孕是什么原因| 孕妇腰疼是什么原因| 垂体催乳素高是什么原因| 医保报销是什么意思| 身上长红疙瘩很痒是什么原因| 亟是什么意思| ym是什么衣服品牌| 喝酒后肚子疼什么原因| 钠氯偏低是什么原因| 早上七点是什么时辰| 温字五行属什么| 摘胆对身体有什么影响| 风湿性关节炎用什么药| 肌酐高是什么原因造成的| 龙脉是什么意思| 想睡睡不着是什么原因| 霸王龙吃什么| 咳嗽什么原因引起的| 提携是什么意思| 宝五行属什么| 头痛做什么检查| 什么人从来不看医生| 市长是什么级别| 农历九月是什么月| 查血压高挂什么科室| 病毒疣是什么| prada是什么牌子| 无能为力是什么意思| 中性粒细胞百分比偏低是什么意思| 什么是反流性食管炎| 世界上最小的长度单位是什么| 香港奶粉为什么限购| 眼结石是什么原因引起的| 胃凉是什么原因| 牛跟什么相冲| 舌头发白是什么原因| 百度

Americas

Asia

Oceania

Contributing Writer
Updated

2018春节专题:瑞犬迎新春 两岸庆吉祥

News Analysis
Apr 16, 20257 mins
GovernmentThreat and Vulnerability Management

After DHS did not renew its funding contract for reasons unspecified, MITRE’s 25-year-old Common Vulnerabilities and Exposures (CVE) program was slated for an abrupt shutdown on April 16, which would have left security flaw tracking in limbo. CISA stepped in to provide a bridge.

百度 据悉,该清单暂定包含7类、128个税项产品,按2017年统计,涉及美对华约30亿美元出口。

Homeland Security sign in Washington, D.C.
Credit: Jerome460 / Shutterstock

Important update April 16, 2025: Since this story was first published, CISA signed a contract extension that averts a shutdown of the MITRE CVE program.

A CISA spokesperson sent CSO a statement saying, “The CVE Program is invaluable to cyber community and a priority of CISA. Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services. We appreciate our partners’ and stakeholders’ patience.” Sources say the contract extension will last 11 months.

Yosry Barsoum, vice president and director of the Center for Securing the Homeland at MITRE, commented: “Thanks to actions taken by the government, a break in service for the Common Vulnerabilities and Exposures (CVE®) Program and the Common Weakness Enumeration (CWE™) Program has been avoided. As of Wednesday morning, April 16, 2025, CISA identified incremental funding to keep the Programs operational. We appreciate the overwhelming support for these programs that have been expressed by the global cyber community, industry, and government over the last 24 hours. The government continues to make considerable efforts to support MITRE’s role in the program and MITRE remains committed to CVE and CWE as global resources.”

April 15, 2025: In a stunning development that demolishes a cornerstone of cybersecurity defense, nonprofit R&D organization MITRE said that its contract with the Department of Homeland Security (DHS) to maintain the Common Vulnerabilities and Exposures (CVE) database, which organizes computer vulnerabilities, will expire at midnight on April 16.

Yosry Barsoum, vice president and director of the Center for Securing the Homeland at MITRE, wrote in a missive to the CVE board, “On Wednesday, April 16, 2025, funding for MITRE to develop, operate, and modernize the Common Vulnerabilities and Exposures (CVE®) Program and related programs, such as the Common Weakness Enumeration (CWE™) Program, will expire. The government continues to make considerable efforts to support MITRE’s role in the program, and MITRE remains committed to CVE as a global resource.”

End of CVE program seen as ‘tragic’

Sasha Romanosky, senior policy researcher at the Rand Corporation, branded the end to the CVE program as “tragic,” a sentiment echoed by many cybersecurity and CVE experts reached for comment.

“CVE naming and assignment to software packages and versions are the foundation upon which the software vulnerability ecosystem is based,” Romanosky said. “Without it, we can’t track newly discovered vulnerabilities. We can’t score their severity or predict their exploitation. And we certainly wouldn’t be able to make the best decisions regarding patching them.”

Ben Edwards, principal research scientist at Bitsight, told CSO, “My reaction is sadness and disappointment. This is a valuable resource that should absolutely be funded, and not renewing the contract is a mistake.”

He added “I am hopeful any interruption is brief and that if the contract fails to be renewed, other stakeholders within the ecosystem can pick up where MITRE left off. The federated framework and openness of the system make this possible, but it’ll be a rocky road if operations do need to shift to another entity.”

MITRE’s CVE program foundational to cybersecurity

MITRE’s CVE program is a foundational pillar of the global cybersecurity ecosystem and is the de facto standard for identifying vulnerabilities and guiding defenders’ vulnerability management programs. It provides foundational data to vendor products across vulnerability management, cyber threat intelligence, security information, event management, and endpoint detection and response.

Although the National Institute of Standards and Technology (NIST) enriches the MITRE CVE records with additional information through its National Vulnerability Database (NVD), and CISA has helped enrich MITRE’s CVE records with its “vulnrichment” program due to funding shortfalls in the NVD program, MITRE is the originator of the CVE records and serves at the primary source for identifying security flaws.

“If MITRE’s funding goes away, it causes an immediate cascading effect that will impact vulnerability management on a global scale,” Brian Martin, vulnerability historian, CSO of the Security Errata project, and former CVE board member, wrote on LinkedIn.

“First, the federated model and CVE Numbering Authorities (CNA) can no longer assign IDs and send info to MITRE for quick publication. Second, all of that is the foundation for the National Vulnerability Database (NVD), which is already beyond struggling, with a backlog of over 30,000 vulnerabilities and the recent announcement of over 80,000 ‘deferred’ (meaning will not be fully analyzed by their current standards).”

Martin added, “Third, every company that maintains ‘their own vulnerability database’ that is essentially lipstick on the CVE pig will have to find alternate sources of intelligence. Fourth, national vulnerability databases like China’s and Russia’s, among others, will largely dry up (Russia more than China). Fourth [sic], hundreds, if not thousands, of National / Regional CERTs around the world, no longer have that source of free vulnerability intelligence. Fifth [sic], every company in the world that relied on CVE/NVD for vulnerability intelligence is going to experience swift and sharp pains to their vulnerability management program.”

Why is the contract ending?

It’s unclear what led to DHS’s decision to end the contract after 25 years of funding the highly regarded program. The Trump administration, primarily through Elon Musk’s Department of Government Efficiency initiative, has been slashing government spending across the board, particularly at the Cybersecurity and Infrastructure Security Agency (CISA), through which DHS funds the MITRE CVE program.

Although CISA has already been through two funding cuts, press reports suggest that nearly 40% of the agency’s staff, or around 1,300 employees, are still slated for termination. However, sources say that compared to the budget cuts made elsewhere in the federal government, the expense of running the CVE program are minor and “won’t break the bank.”

What happens next?

Sources close to the CVE program say that starting at midnight on April 16, MITRE will no longer add records to its CVE database. However, historical CVE records will be available on GitHub.

The real question is whether a private sector alternative to MITRE’s program emerges.

“It’s difficult to speculate on what services could be impacted reading the note from MITRE,” Patrick Garrity, a security researcher at threat intelligence firm Vulncheck, told CSO. “The current vulnerability ecosystem is fragile after seeing NIST NVD’s failure last year, and any impacts to the CVE Program could have detrimental impacts on defenders and the security community. VulnCheck remains committed to helping fill any gaps that might arise.”

Garrity posted on LinkedIn, “Given the current uncertainty surrounding which services at MITRE or within the CVE Program may be affected, VulnCheck has proactively reserved 1,000 CVEs for 2025,” adding that Vulncheck “will continue to provide CVE assignments to the community in the days and weeks ahead.”

A CISA spokesperson told CSO, “CISA is the primary sponsor for the Common Vulnerabilities and Exposure (CVE) program, which is used by government and industry alike to disclose, catalog, and share information on technology vulnerabilities that can put the nation’s critical infrastructure at risk.  Although CISA’s contract with the MITRE Corporation will lapse after April 16, we are urgently working to mitigate impact and to maintain CVE services on which global stakeholders rely.”

This article was originally published April 15, titled “CVE program faces swift end after DHS fails to renew contract, leaving security flaw tracking in limbo.” It has been updated to reflect the latest announcements about CVE.

Show me more

关节痛挂号挂什么科 拍立得相纸为什么这么贵 斑鸠是什么意思 龟苓膏不能和什么一起吃 知柏地黄丸治什么病
五月是什么季节 肩宽适合穿什么样的衣服 为什么会堵奶 中暑是什么症状表现 乳房挂什么科
线束是什么意思 什么是便秘 食神生财是什么意思 恶风是什么意思 凤凰指什么生肖
生脉饮适合什么人喝 福字挂在家里什么位置最合适 熤是什么意思 阑尾为什么会发炎 秋天开什么花
什么地腐烂hcv8jop4ns7r.cn roma是什么意思dajiketang.com co2是什么hcv9jop3ns0r.cn 爱新觉罗是什么民族bysq.com 胯骨疼是什么原因hcv8jop4ns4r.cn
减肥期间适合喝什么酒dajiketang.com 金达莱是什么花hcv9jop2ns5r.cn 脖子大是什么原因hcv9jop5ns5r.cn 为什么要活着hcv9jop2ns7r.cn 扁桃体发炎吃什么药效果好hcv8jop8ns4r.cn
幼小衔接是什么意思hcv8jop8ns9r.cn 血用什么能洗掉hcv9jop1ns5r.cn 倒模是什么意思hcv8jop3ns1r.cn 蛔虫属于什么动物xscnpatent.com 18是什么生肖hcv8jop7ns1r.cn
资深是什么意思hcv7jop7ns2r.cn 什么堂大什么hcv9jop5ns6r.cn 猕猴桃什么时候上市hcv7jop6ns4r.cn 治疗狐臭最好的方法是什么hcv8jop5ns7r.cn 王妃是什么意思hcv8jop3ns9r.cn
百度