CVE Records: The Cybersecurity Glow-Up You Didn’t Know You Needed

Julia Turkovich (SIS Lead CVE Numbering Authority Recruiter · US Cybersecurity and Infrastructure Security Agency (CISA)), Reena Rakipi (Strategic Partnerships in Vulnerability Program Development · US Cybersecurity and Infrastructure Security Agency (CISA))

CVE/FIRST VulnCon 2025 · Main Stage

Overview

In a compelling presentation at VulnCon, Julia Turkovich and Reena Rakipi from the U.S. government's Cybersecurity and Infrastructure Security Agency (CISA) illuminated the critical need for "glowing up" Common Vulnerabilities and Exposures (CVE) records. Their talk, "CVE Records: The Cybersecurity Glow-Up You Didn’t Know You Needed," argued that while CVEs form the essential backbone of vulnerability management, their true potential for enabling effective cyber defense remains largely untapped without comprehensive enrichment. This "glow-up" refers to a fundamental transformation of basic CVE entries into robust, actionable intelligence through the inclusion of crucial contextual data.

Watch on YouTube

Visual summary for CVE Records: The Cybersecurity Glow-Up You Didn’t Know You Needed by Julia Turkovich, Reena Rakipi
Visual summary for CVE Records: The Cybersecurity Glow-Up You Didn’t Know You Needed by Julia Turkovich, Reena Rakipi

Key moments

  1. 0:00 Welcome and speaker introductions
  2. 0:46 Understanding CISA's CVE Numbering Authority recruitment
  3. 3:22 Reena's background in vulnerability management & secure design
  4. 5:37 CISA's mission and CVE program alignment
  5. 6:40 CVE program: backbone of effective vulnerability management
  6. 7:18 CVE enables global collaboration for risk reduction

CVE Records: The Cybersecurity Glow-Up You Didn’t Know You Needed

Speakers: Julia Turkovich, CISA Lead CVE Numbering Authority Recruiter; Reena Rakipi, CISA Strategic Partnerships in Vulnerability Program Development

Conference: VulnCon

YouTube: https://www.youtube.com/watch?v=WPdv8LMZfRY

Overview

In a compelling presentation at VulnCon, Julia Turkovich and Reena Rakipi from the U.S. government's Cybersecurity and Infrastructure Security Agency (CISA) illuminated the critical need for "glowing up" Common Vulnerabilities and Exposures (CVE) records. Their talk, "CVE Records: The Cybersecurity Glow-Up You Didn’t Know You Needed," argued that while CVEs form the essential backbone of vulnerability management, their true potential for enabling effective cyber defense remains largely untapped without comprehensive enrichment. This "glow-up" refers to a fundamental transformation of basic CVE entries into robust, actionable intelligence through the inclusion of crucial contextual data.

The speakers, both deeply involved in the CVE program at CISA, underscored that a basic CVE ID, description, and reference are merely the starting point. To genuinely empower cyber defenders, CVE records must be enriched with Common Weakness Enumeration (CWE) and Common Vulnerability Scoring System (CVSS) metrics, particularly the detailed vector string. This additional context moves beyond simply identifying a vulnerability to explaining its root cause, potential impact, and severity, thereby enabling targeted remediation and strategic risk reduction. CISA, as the sole sponsor of the CVE program, is actively driving this transformation through its vulnerrichment efforts and proactive recruitment and coaching of CVE Numbering Authorities (CNAs).

The significance of this initiative cannot be overstated. In an increasingly complex threat landscape, defenders are often overwhelmed by the sheer volume of vulnerability disclosures. Incomplete or ambiguous CVE records lead to misaligned priorities, wasted resources, and prolonged exposure to exploitable flaws. By advocating for and implementing a standardized approach to CVE enrichment, CISA aims to fortify the global cybersecurity ecosystem, making vulnerability information more useful, accessible, and a single source of truth for all stakeholders—from vendors and researchers to government agencies and critical infrastructure operators.

Background

▶ Watch: Welcome and speaker introductions (0:00)

CISA operates as America's cyber defense agency and the national coordinator for critical infrastructure resilience, a mission deeply intertwined with effective vulnerability management. The CVE Program, whose mission is to identify, define, and catalog publicly disclosed vulnerabilities, serves as the universal language for communicating vulnerability information across diverse industries, time zones, and countries. While CVEs are foundational, the speakers emphasized that their utility is directly proportional to the quality and completeness of the data they contain.

Historically, a basic CVE record has been defined by three required components: the CVE ID (the unique identifier), a description of the vulnerability, and at least one reference link to additional information. However, CISA analysts and cybersecurity practitioners consistently highlight the need for more. A truly high-quality record, as articulated by the speakers, includes a comprehensive list of affected products and their versions, details on available patches, and workaround guidance within its description. Similarly, robust reference links might encompass contributions from the original researcher, the authoring CNA, and even proof-of-concept (PoC) code repositories.

The concept of a "glow-up," borrowed from popular culture, perfectly encapsulates the program's ambition for CVE records. It's not merely a superficial makeover but a profound enhancement that strengthens the underlying foundation, making it more resilient and effective. Analogies such as Mia Thermopolis's transformation in "The Princess Diaries," Steve Rogers becoming Captain America, the evolution from Windows 95 to Windows 11, and Luke Skywalker's journey to becoming a Jedi Master, were used to illustrate this concept. In each case, a strong but underdeveloped foundation was transformed through enrichment and training, unlocking its full potential.

The current state of CVE data reveals a significant gap. In the past year, out of 23,000 CVE records produced by 284 CNAs, only close to 12,000 included both CWE and CVSS. A larger proportion, 71%, included CWE, while just 53% featured CVSS. This data deficit means that a substantial number of CVEs lack the critical context necessary for defenders to prioritize and act effectively. Without CWE (which explains the underlying weakness or root cause) and CVSS (a standardized scoring system assessing technical impact and severity, particularly its detailed vector string), security teams are left to guess, misaligning resources and potentially leaving critical vulnerabilities unaddressed. CISA's focus is to minimize this gap, ensuring that CVE records provide a clear, actionable roadmap for cyber defense.

Key Findings

▶ Watch: Reena's background in vulnerability management & secure design (3:22)

The central finding of the talk is that enriched CVE records are not just a desirable feature but a critical necessity for effective vulnerability management and national cyber defense. The speakers demonstrated that a basic CVE record, while providing a unique identifier, falls short in equipping defenders with the actionable intelligence needed to make informed decisions. The "glow-up" of CVE records, primarily through the consistent inclusion of CWE and CVSS (especially the vector string), directly translates into several key benefits and findings:

  1. Enhanced Prioritization and Actionability: Enriched records provide the context (root cause via CWE, technical impact/severity via CVSS) that transforms a simple vulnerability identifier into a clear roadmap for defenders. This allows security teams to prioritize remediation efforts based on actual risk to their unique environments, rather than making educated guesses.
  2. Proactive Defense and "Secure by Design": The consistent use of CWE helps identify recurring patterns and underlying weaknesses across systems. This enables organizations to shift from reactive "whack-a-mole" vulnerability patching to a more proactive, "secure by design" approach, addressing classes of vulnerabilities at the source within their Software Development Lifecycle (SDLC).
  3. Improved Resource Allocation: By understanding the root cause and potential impact, organizations can better allocate resources, such as advocating for specific developer training to address common weaknesses or grouping vulnerabilities for more efficient defensive measures (e.g., firewall rules).
  4. CISA's Active Role in Data Enrichment: CISA is not just advocating for this change but actively implementing it through its vulnerrichment program. This involves adding SSVC (Stakeholder-Specific Vulnerability Categorization) decision points, flagging Known Exploited Vulnerabilities (KEV), and proactively adding missing CWE and CVSS information to existing CVE records where CNAs have not provided it. This demonstrates CISA's commitment to improving data quality for all consumers.
  5. Strategic CNA Recruitment and Coaching: CISA’s efforts extend to the source of CVEs—the CNAs. Through rigorous recruitment focusing on transparency and a willingness to share, and continuous coaching (including refresher trainings and working group participation), CISA is fostering a community of CNAs committed to publishing complete, accurate, and timely records. This has shown tangible results, with 95% of records from CNAs under the CISA ICS root including CWE, and 64% including CVSS.
  6. Community-Driven Improvement: The talk underscored that the CVE program's strength lies in its community. Feedback from researchers on accuracy, input from downstream users on missing data points, and active participation in working groups are all crucial for refining the program and its data quality. This collaborative approach ensures that the "glow-up" is aligned with the practical needs of the cybersecurity community.

In essence, the key finding is that a collective, concerted effort to enrich CVE records with contextual data points like CWE and CVSS is paramount for transitioning from basic vulnerability awareness to advanced, risk-informed cyber defense.

Technical Deep Dive

▶ Watch: CISA's mission and CVE program alignment (5:37)

The technical core of the "CVE Records Glow-Up" lies in the strategic integration and utilization of CWE and CVSS within the existing CVE framework. While the foundational requirements for a CVE record remain the CVE ID, a description, and at least one reference link, the speakers detailed how enriching these elements fundamentally transforms their utility.

A quality description, for instance, goes beyond a generic statement, providing a comprehensive list of affected products and their versions, crucial patch information, and practical workaround guidance. Similarly, effective reference links should aggregate information from the original researcher, the authoring CNA, and even public Proof-of-Concept (PoC) repositories, offering a holistic view of the vulnerability.

Common Weakness Enumeration (CWE)

CWE is presented as the "force within the vulnerability," providing the root cause or underlying weakness that led to the vulnerability. Maintained by MITRE, CWE helps defenders understand why vulnerabilities occur, moving beyond mere symptom treatment.

Benefits of CWE:

  • Root Cause Analysis: Helps identify the fundamental flaws in software design or implementation.
  • Proactive Defense: Enables the identification and elimination of entire classes of vulnerabilities, supporting secure by design principles in the SDLC.
  • Trend Spotting: Security researchers and teams can spot recurring patterns of weaknesses across systems or specific codebases.
  • Resource Allocation: Managers can advocate for targeted training for engineering teams based on clusters of similar CWEs, improving overall code quality.
  • Network Defense Optimization: Allows for grouping similar problems to create more efficient firewall rules and other defensive measures, as opposed to ad-hoc responses for individual vulnerabilities.

Challenges with CWE Assignment:

  • Complexity and Time-Consumption: The vast number of CWEs and the nuance required for accurate mapping can be daunting.
  • Inconsistency: Varying interpretations and methodologies across CNAs and organizations lead to inconsistent assignments.
  • Difficulty in Pinpointing: Identifying the precise root cause can be challenging, especially for complex vulnerabilities.
  • Manual Effort: The process is often manual, requiring significant time and resources.
  • Knowledge Gaps: A lack of expertise or training among assigners.
  • Vendor Reluctance: Some vendors are unsure about the value or implications of publicly disclosing the underlying weakness.

Solutions for CWE Improvement:

  • Root Cause Mapping Working Group: Participation in groups like this (run by MITRE) helps refine identification processes.
  • Hierarchical Mapping: Start at a broader "parent" CWE, then leverage recently added mapping notes to drill down to the most precise CWE.
  • AI-Powered Tools: Explore solutions like the CNA Guru chatbot (mentioned as presented by AWS) or other AI initiatives from the Root Cause Mapping Group to streamline and automate assignment.
  • Community Input: Active participation from the community is essential to refine CWE definitions and mapping guidance.
  • Transparency Advocacy: Educate vendors on the value of disclosing weaknesses to customers, demonstrating accountability and transparency.

Common Vulnerability Scoring System (CVSS)

CVSS is the standardized scoring system that assesses the potential technical impact and severity of a vulnerability. While a base score provides a general indication, the vector string is particularly emphasized for its detailed context.

Benefits of CVSS:

  • Prioritization: Allows organizations to prioritize remediation efforts by understanding the potential impact on their specific systems.
  • Impact Assessment: Helps developers understand how vulnerabilities might affect their code and systems.
  • Communication Standard: Enables national CERTs and other agencies to communicate important vulnerability properties consistently.
  • Risk Management: Provides senior leadership with a high-level understanding of organizational risk.
  • Environmental Context: When combined with temporal and environmental metrics, the base score becomes highly relevant to a specific operational context.

Challenges with CVSS Assignment:

  • Base Score Over-reliance: Many tools and users often rely solely on the base score, which is a general vendor-provided assessment, rather than incorporating environment-specific context.
  • Time-Consuming: Accurately calculating and assigning CVSS metrics can be a lengthy process.
  • Metric Selection Difficulty: Choosing the correct metrics for the vector string can be complex and prone to error.
  • Lack of Environment Specificity: Base vector strings are inherently generic and do not account for unique environmental factors.

Solutions for CVSS Improvement:

  • Vector String Utilization: Employ tools that use the full vector string as an input, not just the base score.
  • Migration to CVSS Version 4: Speakers strongly recommend adopting CVSS version 4, citing its improved simplicity, better pairing with SSVC (Stakeholder-Specific Vulnerability Categorization), and the retirement of the often-controversial scope metric.
  • Reference SIG Examples: Consult the CVSS SIG's (Special Interest Group) examples for guidance on constructing accurate vector strings.
  • Enhance with Environmental/Threat Metrics: Combine the base vector string with organization-specific threat and environmental metrics to derive a more accurate, risk-informed decision. This is crucial as the base metric is only the developer's best guess.

CISA's Vuln Enrichment Efforts

CISA actively "walks the walk" by implementing its own vulnerrichment program to "glow up" CVE records. This involves:

  • SSVC Integration: CISA provides the first three decision points of SSVC (exploitability, impact, and automatability) to aid in prioritization, particularly for critical infrastructure protection.
  • KEV Flagging: CISA flags vulnerabilities that are part of its Known Exploited Vulnerabilities (KEV) catalog, signaling immediate attention for defenders.
  • Missing Data Filling: CISA proactively adds missing CWE and CVSS information to records when CNAs have not provided it. This is done to the best of CISA's ability based on the provided description.
  • Dynamic and Feedback-Driven: All CISA additions are dynamic. If a CNA subsequently updates their record with their own CWE or CVSS, CISA's additions are automatically removed. A GitHub feedback loop allows users to request corrections or provide input on CISA's assignments.
  • Automated Ingestion: For CVE consumers, these enrichments are automatically ingested, ensuring they always have the most updated and comprehensive information without requiring separate subscriptions.

By focusing on these technical details and actively contributing to the enrichment process, CISA aims to elevate the CVE program from a basic catalog to a powerful, actionable intelligence resource.

Demo / Proof of Concept

▶ Watch: CVE program: backbone of effective vulnerability management (6:40)

While the talk didn't feature a live technical demonstration or proof of concept in the traditional sense, the speakers effectively illustrated the concept of a "glow-up" through examples of well-enriched CVE records and CISA's internal processes. Instead of a live hack or tool showcase, the presentation served as a conceptual demonstration, highlighting the tangible differences between a basic CVE entry and a fully enriched one.

Reena Rakipi presented an example of a CVE record published by the ICSERT CNA (a CISA-affiliated CNA) that, in their opinion, "does not need a glow up." This exemplary record prominently featured a CVSS score with a complete vector string, a CWE assignment, and a detailed description that included specific product versions, vendor names, and comprehensive product information. This served as a visual "proof of concept" for what a complete and actionable CVE record looks like. The anecdote about Art Manion's son writing this record, presumably under rigorous guidance, further underscored the effort required to achieve such quality.

Additionally, the discussion around CISA's vulnerrichment efforts, including the addition of SSVC decision points, KEV flags, and the proactive filling of missing CWE and CVSS data, served as a demonstration of CISA's commitment to enhancing CVE records. The mention of specific tools like Phonogram for different scoring scenarios and the CNA Guru chatbot (though presented by AWS, not CISA directly in this talk) also alluded to the practical applications and evolving landscape of CVE enrichment tools, even if not directly demonstrated. The GitHub feedback loop for CISA's additions was also presented as a functioning mechanism for community engagement and quality control, acting as a "proof" of the dynamic and collaborative nature of their enrichment.

Defensive Implications

▶ Watch: CVE enables global collaboration for risk reduction (7:18)

The "CVE Records Glow-Up" initiative carries profound implications for cyber defenders, offering a clearer, more actionable path to managing and mitigating vulnerabilities. The core message empowers defenders to transition from reactive patching to proactive, risk-informed strategies.

For Security Teams and Downstream CVE Users:

  1. Prioritized Remediation: Defenders should actively seek out and leverage enriched CVE records that include CWE and CVSS vector strings, along with SSVC decision points and KEV flags. This data provides the necessary context to move beyond a simple "critical" rating and prioritize vulnerabilities based on their actual exploitability, impact, and relevance to their specific environment. As noted by a Verizon attendee, if "a million criticals" exist, nothing is truly critical; proper CVSS utilization, including temporal and environmental scores, allows for genuine prioritization.
  2. Strategic Resource Allocation: Understanding the CWE (root cause) allows security teams to identify systemic weaknesses. This knowledge can inform decisions to invest in developer training, update secure coding guidelines, or re-architect vulnerable components to eliminate entire classes of vulnerabilities, aligning with "secure by design" principles.
  3. Enhanced Network Defenses: As articulated by an attendee, CWE can guide the creation of more effective firewall rules and other defensive measures, grouping similar problems rather than requiring individual responses for every single CVE.
  4. Leveraging CVSS Version 4: Defenders should advocate for and adopt CVSS version 4, which offers a simpler, more understandable framework that pairs well with SSVC and provides better context for environmental tailoring. They should utilize tools that consider the full CVSS vector string as an input, not just the base score, and integrate their own threat and environmental metrics to refine the base score for their unique context.
  5. Active Engagement with CISA's Enrichment: Defenders should utilize CISA's vulnerrichment additions, including the SSVC and KEV flags. Crucially, they should engage with the GitHub feedback loop to provide input on CISA's assignments or suggest improvements, ensuring the data remains accurate and useful.
  6. Demand for Completeness: Downstream users have a voice. They should actively communicate to CNAs and CISA what data points are missing or most valuable in CVE records. This feedback drives the program's evolution and encourages greater completeness from the source.

For Vendors and CVE Numbering Authorities (CNAs):

  1. Commitment to Data Quality: CNAs are at the forefront of the "glow-up." They must commit to publishing complete, accurate, and timely CVE records. This includes consistently adding CWE and CVSS vector strings to their disclosures.
  2. Transparency and Accountability: Embracing the philosophy of sharing vulnerabilities, both internally discovered and externally reported, demonstrates accountability to customers. Publishing a CVE, even for "dirty laundry," ultimately builds trust and contributes to collective defense.
  3. Active Participation in Working Groups: CNAs should participate in relevant working groups such as the CNA Organization of Peers, the Root Cause Mapping Group, and the CWE/CVE User Experience Working Group. These forums provide opportunities to share best practices, address challenges, and contribute to the evolution of the program.
  4. Leveraging Tools and Guidance: CNAs should explore and adopt tools that streamline CWE and CVSS assignment, such as AI-powered solutions or the detailed mapping notes for CWEs. They should also refer to CVSS SIG examples and engage with the SIG leaders to improve guidance.
  5. Proactive Coaching and Mentoring: CISA's CNA recruitment and coaching program offers valuable support. New and existing CNAs should take advantage of refresher trainings, demos of CVE services (like Phonogram for different scoring scenarios), and guidance on selecting correct CWEs.

Ultimately, the defensive implications underscore that a robust, enriched CVE ecosystem fosters a more resilient cyber landscape. By working collaboratively—CNAs providing rich data, CISA enriching where gaps exist, and defenders actively consuming and providing feedback—the entire community benefits from more informed decision-making and a stronger collective defense against evolving threats.

Key Takeaways

  • Enriched CVE Records are Essential: Basic CVE IDs are insufficient; comprehensive enrichment with CWE and CVSS (especially the vector string) is critical for effective vulnerability management and informed decision-making by cyber defenders.
  • CWE Enables Proactive Defense: Common Weakness Enumeration (CWE) provides the root cause of vulnerabilities, allowing organizations to identify trends, allocate resources for training, and implement "secure by design" principles to eliminate entire classes of weaknesses.
  • CVSS is Key for Prioritization: Common Vulnerability Scoring System (CVSS), particularly CVSS version 4 and its detailed vector string, is vital for assessing technical impact and severity. When combined with environmental and temporal metrics, it enables accurate, context-specific prioritization of remediation efforts.
  • CISA Actively Drives Enrichment: CISA is not just advocating but actively "glowing up" CVE records through its vulnerrichment program, adding SSVC decision points, flagging Known Exploited Vulnerabilities (KEV), and filling in missing CWE and CVSS data, with a transparent GitHub feedback loop.
  • CNA Commitment is Paramount: CVE Numbering Authorities (CNAs) are the primary source of high-quality vulnerability data. CISA actively recruits and coaches CNAs to promote transparency, accountability, and the consistent publication of complete, accurate, and timely records, leading to tangible improvements in data quality (e.g., 95% CWE inclusion from CISA's ICS root CNAs).
  • Community Engagement is Crucial: The success of the CVE program's "glow-up" depends on active participation from all stakeholders—CNAs providing data, researchers offering feedback, and downstream users communicating their needs—to ensure the CVE ecosystem remains valuable, trustworthy, and responsive to evolving threats.

About the Speaker(s)

Julia Turkovich serves as CISA's Lead CVE Numbering Authority Recruiter. In this role, she is responsible for extensive outreach to companies, researchers, and organizations, encouraging them to join the CVE program as partners. Her work is crucial for expanding the CVE ecosystem, particularly within CISA's root scope of industrial control systems, medical devices, and critical infrastructure, where vulnerabilities can have catastrophic impacts. In her two and a half years at CISA, she has proudly onboarded over 40 organizations. Julia is also a familiar voice to the community, hosting segments on the CVE program's podcast, including discussions on the Council of Roots and "Myths vs Facts" about CNA recruitment.

Reena Rakipi is involved in Strategic Partnerships in Vulnerability Program Development at CISA. With a strong background in communication, Reena previously worked in CISA's production shop, where she helped author joint advisories for vulnerabilities exploited in the wild by nation-state actors. Notably, she co-created the "Secure by Design" alerts series, which focuses on eliminating entire classes of vulnerabilities, demonstrating her passion for proactive security measures. Her dedication to this topic led her to the vulnerability management side of CISA, where she now focuses on communicating actionable information to defenders and advocating for the elimination of vulnerability classes through initiatives like the CVE "glow-up."

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A well-intentioned but lightweight advocacy talk from two CISA staffers pushing for better CVE record quality. The core message — enrich your CVEs with CWE and CVSS vector strings — is correct and genuinely matters for the ecosystem, and CISA's vulnerrichment program is real work worth knowing about. But this is a practitioner awareness session dressed up with pop-culture analogies and program marketing, not a substantive policy or technical briefing. The data points presented (53% CVSS inclusion, 71% CWE) are useful but thin, the recommendations are generic, and neither speaker is close enough to rulemaking or technical depth to say something a VulnCon attendee couldn't have found in…

Heather Calloway (CISO) — SOLID

A competent, well-intentioned talk from CISA practitioners making a real case for CVE record quality improvement. The argument is sound — incomplete CVE records degrade defensive decision-making, and the gap is measurable — but the presentation stays in program advocacy mode rather than delivering something that changes how a security leader thinks or acts. Useful for vulnerability program managers and CNAs. Limited ceiling for CISOs and above.

→ Top-rated talks at CVE/FIRST VulnCon 2025

All talks from CVE/FIRST VulnCon 2025