CyberMax
Home › Glossary › Vulnerability management

What is a CNA (CVE Numbering Authority)?

Vulnerability management glossary · 1 primary source

An organisation authorised by the CVE Program to assign CVE IDs and publish CVE records for vulnerabilities in its scope.

Large vendors are usually the CNA for their own products, so a flaw in their software gets its CVE straight from them. Others cover open-source ecosystems, a country, or act as a CNA of last resort.

Because the CNA writes the record, quality and detail vary: some add CVSS scores, CWE weakness types and exact version ranges, others only a short description.

Sources

Related terms

On this site

All vulnerability management terms · Full glossary