The Common Vulnerabilities and Exposures (CVE) program is dedicated to analyzing vulnerabilities, then to assigning a unique ID to them and disclosing the vulnerabilities to affected software vendors. A CVE Numbering Authority (CNA) is a key partner in the CVE program responsible for assigning an official ID to a CVE and registering a description of the vulnerability in order to communicate it to the other CNAs and the affected software vendors. To avoid the disclosure of vulnerabilities before the development of a fix, the CNAs and the affected vendors need to coordinate a proper schedule for the disclosure of vulnerabilities and the release of their fixes through multi-party coordination. This paper analyzes the practices used by CNAs to coordinate on vulnerability fix releases and disclosure by empirically studying the 13 CNAs that assigned the most CVEs from 2010 to 2020 and are also software vendors. Our results show that the studied CNAs discover and assign CVE IDs for the majority of vulnerabilities that affect their own products, which we refer to as self-assigned vulnerabilities. While the vulnerabilities that are assigned for other CNAs’ products, which we refer to as delegated vulnerabilities, tend to be more severe than the self-assigned vulnerabilities, (median Common Vulnerability Scoring System score of 7.5), we observe that their fixes are released at a slower pace. Moreover, when such a delegated vulnerability affects several CNAs’ products, the fixes are released a median of 4 days after the disclosure date, with a median delay between the first and last patch releases of those products of 35 days up to more than one year, which corresponds to a large window of exploitation.
Data Availability Statement
The data that support the findings of this study are available on the CVE (cve 2022) and https://www.tenable.com websites.
Note that we use https://www.tenable.com, since the open-source vulnerability database (OSVDB), which was widely used to study the patch available date for security vulnerabilities (Frei et al. 2006; Shahzad et al. 2012), was shutdown permanently in 2016, https://www.securityweek.com/osvdb-shut-down-permanently.
Lin, J., Adams, B. & Hassan, A.E. On the coordination of vulnerability fixes. Empir Software Eng 28, 151 (2023). https://doi.org/10.1007/s10664-023-10403-x
