The National Institute of Standards and Technology (NIST) is grappling with a significant backlog in its National Vulnerabilities Database (NVD) due to recent funding cutbacks. A cybersecurity company has found that over 93 percent of the flaws added to the database have not been analyzed or enhanced, which poses a substantial risk to organizational security.
VulnCheck researcher Patrick Garrity highlighted that while the database struggles, threat actors continue to exploit vulnerabilities, increasing the urgency of the situation. “Nation-state threat actors and ransomware gangs continue to target organizations with devastating consequences, while our own house is in disarray,” he wrote.
NIST’s budget was reduced by nearly 12 percent this year, impacting its capacity to keep the NVD current. Following the announcement of budget cuts in February, NIST warned of delays in vulnerability analysis. By April, the agency prioritized the most significant vulnerabilities and considered collaborating with the private sector to address the backlog. NIST is also exploring long-term solutions, including forming a consortium to maintain the database’s relevance and accuracy.
VulnCheck’s analysis revealed that out of 12,720 CVEs published between February and May, 11,885 remain unanalyzed. This includes 56 percent of weaponized vulnerabilities and 82 percent with proof-of-concept exploits. The lack of analysis is troubling, given that the NVD has been a crucial resource for global security teams for over two decades, providing enriched vulnerability data and maintaining accountability for CVE number authorities and vendors.
The situation calls for a community response, Garrity argues. He urges organizations to coordinate efforts to fill the void left by NIST, recommending that CNAs provide more comprehensive data and that CVE enrichment be automated where possible. He also suggests that initiatives like CISA’s Vulnrichment project could be integrated to enhance the data further.
Source: Security Boulevard
–
May 31, 2024 – by Cass Kennedy
Follow Us