Confusing Value with Enumeration: Studying the Use of CVEs in Academia

Moritz Schloegel, Daniel Klischies, Simon Koch, David Klein, Lukas Gerlach, Malte Wessels, Leon Trampert, Martin Johns, Mathy Vanhoef, DistriNet, Michael Schwarz, Thorsten Holz, Jo Van Bulck, DistriNet

34th USENIX Security Symposium · Day 1

This distinguished paper from USENIX Security 2025, titled "Confusing Value with Enumeration: Studying the Use of CVEs in Academia," presents a critical and systematic examination of how Common Vulnerabilities and Exposures (CVE) identifiers are used within academic security research. Authored by a collaborative team from leading European institutions including CISPA Helmholtz Center for Information Security, Ruhr University Bochum, TU Braunschweig, and KU Leuven, the research delves into the prevalent misconception that assigning a CVE inherently signifies a serious security issue or real-world impact. The paper argues that academics frequently claim CVEs to demonstrate the practical relevance of their findings, often overlooking the original purpose of CVEs as mere unique identifiers.

AI review

Rigorous meta-science that finally puts numbers behind what practitioners have been complaining about for years: academic CVE-farming is real, a third of claimed CVEs are disputed or unverified, and CNA-LRs (read: MITRE) are the weak link. The methodology is solid and the recommendations are actionable, even if some of the findings confirm what anyone who's maintained an open-source project already knew.