Future of CVE Program in limbo as CISA, board members debate path forward
The future of the central repository for security vulnerabilities is being hotly debated as multiple entities seek to support the effort or create alternatives following a funding incident earlier this year that nearly shuttered the database’s website.
Last week, the Cybersecurity and Infrastructure Security Agency (CISA) released two documents explaining their plans for the CVE Program — a critical cybersecurity resource used globally to catalog thousands of software and hardware bugs.
The CISA documents last week appeared to assert control over the CVE Program after subcontractor MITRE Corporation warned in April that the U.S. government may not renew a contract that funded the CVE.org website and about a dozen analysts who work to support the CVE Program.
Read more at The Record