NIST Ends Routine CVSS Scoring for Vulnerabilities in NVD (heise.de)
- NIST ends routine CVSS scoring in NVD to reduce backlog of 27,000 unanalyzed entries.
- Audit criticizes NIST for poor planning, cites $800,000 waste on CVSS calculations.
- CISA's Vulnrichment project partially overlaps but lacks product-specific CPE data.
"The US National Institute of Standards and Technology (NIST) is ending routine CVSS severity scoring for IT vulnerabilities in its National Vulnerability Database (NVD) to address a backlog of over 27,000 unanalyzed entries. The decision follows a critical audit by the US Department of Commerce Inspector General citing poor planning and wasteful spending. NIST will only calculate CVSS scores when inconsistencies arise or upon request, saving $800,000 over two years. The agency is exploring automated scoring and promises better coordination with CISA."
no comments yet.