CVE Program participant submits the details.
CVE Program partner submits the details.
Details include but are not limited to affected product(s); affected or fixed product versions; vulnerability type, root
cause, or impact; and at least one public reference.
@@ -143,17 +158,23 @@
- A CVE Record is the descriptive data about a vulnerability associated with a CVE ID, provided by a CVE Numbering
- Authority (CNA). This data is provided
- in multiple human and machine-readable formats.
+ A CVE Record is the descriptive data about a vulnerability associated with a CVE ID, provided by a
+
+ CVE Numbering Authority (CNA)
+
+ partner. This data is provided in a human and machine-readable
+
+ format
+ .
-
Each CVE Record includes the following:
+
Each CVE Record includes, at a minimum, the following:
-
CVE ID with four or more digits in the sequence number portion of the ID (i.e., “CVE-1999-0067”, “CVE-2019-12345”,
“CVE-2021-7654321”).
- Brief description of the security vulnerability.
+ - Affected products and versions.
- Any pertinent references (i.e., vulnerability reports and advisories).
A CVE Record is associated with one of the following states:
@@ -172,15 +193,21 @@
so that users know that the CVE ID and CVE Record are invalid.
-
The CVE Program’s CNA Rules include additional helpful information about CVE Records:
+
+ The CVE Program’s
+ CNA Rules
+ include additional helpful information about CVE Records:
+
-
- CVE Record
- Information Requirements – the full requirements for a CVE Record.
+
+ CVE Record Content
+
-
- Assignment Rules
- – the data elements required within a CVE Record.
+
+ CVE ID Assignment
+