You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Reserved-but-public (RBP) IDs come in several flavors.
Vendor CNA publishes official advisory/vulnerability information, there is delay before vendor CNA populate CVE entry
Typographical mistake
Accidentially publishing a valid ID for a not-yet-published vulnerability
Others?
Case 1. is particularly painful for "hot" vulnerabilities, i.e., the period of time that starts when a new vulnerability is published and consumers are scrambling for information, including information provided in and indexed by CVE entries.
The Program should take a comprehensive look and make some decisions about RBP, including:
Reserved-but-public (RBP) IDs come in several flavors.
Case 1. is particularly painful for "hot" vulnerabilities, i.e., the period of time that starts when a new vulnerability is published and consumers are scrambling for information, including information provided in and indexed by CVE entries.
The Program should take a comprehensive look and make some decisions about RBP, including: