Skip to content
lesson Cyber security fundamentals Intermediate 3 min read

What is a CVE?

A CVE is the public reference number for one security vulnerability. Who assigns them, how to read one, and what a severity score adds.

A CVE is an entry in a public catalogue of known security vulnerabilities. The letters stand for Common Vulnerabilities and Exposures. Each entry has its own ID, such as CVE-2014-0160, so that software makers, IT people and the news are all talking about the same problem.

Who runs it

The catalogue is kept by the CVE Program, whose mission is to identify, define and catalogue publicly disclosed cyber security vulnerabilities. The program is sponsored by CISA, the United States cyber security agency. The list was created at the MITRE Corporation and opened to the public in 1999. There is one CVE Record for each vulnerability.

Who assigns the numbers

No single office hands out every number. The program authorises organisations around the world to do it. They are called CVE Numbering Authorities, or CNAs. A CNA can be a software vendor, a security researcher, an open source project, a national response team or a bug bounty provider.

Each CNA has an agreed scope. A software maker that is a CNA, for example, assigns IDs for vulnerabilities in its own products. The usual path looks like this:

  1. Someone discovers a vulnerability and reports it to a CVE Program partner.
  2. The partner reserves a CVE ID for it.
  3. The details are filled in and the record is published on the CVE List for anyone to read.

How to read one

Take CVE-2014-0160, the vulnerability better known as Heartbleed.

  • CVE is the prefix.
  • 2014 is the year the ID was reserved or the vulnerability was made public. It is not the year the flaw was discovered.
  • 0160 is a sequence number of four or more digits. It is arbitrary and carries no meaning.

The record behind the ID holds a short description of the vulnerability, the products and versions affected, and links to reports and advisories. The affected versions are the part to read first.

What a severity score adds

A CVE ID tells you which vulnerability, and nothing about how bad it is. That comes from a separate standard, the Common Vulnerability Scoring System (CVSS), which is maintained by FIRST, the Forum of Incident Response and Security Teams. CVSS gives a score from 0 to 10, which maps to a rating:

  • Low: 0.1 to 3.9
  • Medium: 4.0 to 6.9
  • High: 7.0 to 8.9
  • Critical: 9.0 to 10.0

The score describes the vulnerability itself. It does not say whether anyone is attacking it. For that, CISA keeps a Known Exploited Vulnerabilities catalogue, listed by CVE ID, of vulnerabilities that have been used in real attacks.

Why a business owner should know the term

Security notices from software makers quote CVE IDs, and so do news reports about serious bugs. When one mentions a product you use, three questions settle most of it:

  • Do we run the affected product and version?
  • Has the patch been installed?
  • If there is no patch yet, is there a workaround?

Checking your systems against the list of known vulnerabilities is the core of a vulnerability assessment. For the wider set of controls, see The Essential Eight: where a small business should start.

Sources

  1. Overview: about the CVE Program (CVE.org) cve.org
  2. Process: CVE record lifecycle (CVE.org) cve.org
  3. CVE Numbering Authorities (CVE.org) cve.org
  4. History (CVE.org) cve.org
  5. Common Vulnerability Scoring System (FIRST) first.org
  6. CVSS v4.0 specification document (FIRST) first.org
  7. Known Exploited Vulnerabilities Catalog (CISA) cisa.gov

Written by Only Tech Solutions.

This is general information, not advice for your situation. See the terms and conditions.

We can sort this for you

More lessons

All lessons

Tell us what needs sorting.

Book a call or send an email. We reply within one business day.