What is a CNA (CVE Numbering Authority)?
An organisation authorised by the CVE Program to assign CVE IDs and publish CVE records for vulnerabilities in its scope.
Large vendors are usually the CNA for their own products, so a flaw in their software gets its CVE straight from them. Others cover open-source ecosystems, a country, or act as a CNA of last resort.
Because the CNA writes the record, quality and detail vary: some add CVSS scores, CWE weakness types and exact version ranges, others only a short description.
Sources
Related terms
- CVECommon Vulnerabilities and Exposures: the public ID system for disclosed security flaws, written as CVE-YEAR-NUMBER, for example CVE-2021-44228.
- NVDThe National Vulnerability Database run by NIST, which republishes CVE records and adds analysis such as CVSS scores, CWE types and CPE product names.