Open Discussion - International Challenges with CVD, CNA, and CVE
Reena Rikipi (Strategic Partnerships and Vulnerability Program Lead · CISA), Tommoito (CVD Coordinator · JP Coordination Center)
CVE/FIRST VulnCon 2025 · Open Discussion
Overview
This VulnCon talk, "Open Discussion - International Challenges with CVD, CNA, and CVE," provided a critical forum for cybersecurity professionals to engage in a candid conversation about the complex landscape of Coordinated Vulnerability Disclosure (CVD), the role of CVE Numbering Authorities (CNAs), and the challenges associated with consuming CVE data. Led by Reena Rikipi from the Cybersecurity and Infrastructure Security Agency (CISA) and Tommoito from the JPCERT Coordination Center (JPCERT/CC), the session quickly evolved from a planned tabletop exercise into an interactive dialogue, reflecting the community's urgent need to address these issues collaboratively.

Key moments
- 0:00 Introduction: Speakers and open discussion on CVD, CNA, CVE
- 2:00 Reena's background and audience survey on CVD experience
- 4:00 Audience poll: CNAs, aspiring CNAs, and CVE data users
- 5:00 Introducing the core problem statement for the discussion
- 6:00 Tommoito explains problem: Diverse understandings of CVD
- 7:40 First audience question: CVD case failures due to miscommunication
- 8:00 Verizon's perspective: Receiving vulnerability reports, not a CNA
Open Discussion - International Challenges with CVD, CNA, and CVE
Speakers: Reena Rikipi (CISA), Tommoito (JPCERT/CC)
Conference: VulnCon
YouTube: https://www.youtube.com/watch?v=Nc6sfvp0K88
Overview
This VulnCon talk, "Open Discussion - International Challenges with CVD, CNA, and CVE," provided a critical forum for cybersecurity professionals to engage in a candid conversation about the complex landscape of Coordinated Vulnerability Disclosure (CVD), the role of CVE Numbering Authorities (CNAs), and the challenges associated with consuming CVE data. Led by Reena Rikipi from the Cybersecurity and Infrastructure Security Agency (CISA) and Tommoito from the JPCERT Coordination Center (JPCERT/CC), the session quickly evolved from a planned tabletop exercise into an interactive dialogue, reflecting the community's urgent need to address these issues collaboratively.
The discussion highlighted the inherent complexities and disparities in how CVD is understood and practiced across different organizations and international borders. Speakers and audience members alike shared experiences regarding communication breakdowns, the efficacy of bug bounty programs, the struggle for international coordination beyond national CERTs, and the critical need for harmonized, machine-readable vulnerability information. The conversation underscored that effective vulnerability management is not merely a technical exercise but a socio-technical challenge deeply intertwined with trust, communication, and shared understanding, especially in a globally interconnected threat landscape.
This article delves into the core challenges identified, the proposed solutions, and the strategic implications for vendors, defenders, and the broader cybersecurity community. It emphasizes the importance of moving beyond fragmented approaches towards a more unified, efficient, and trusted global framework for vulnerability coordination, crucial for protecting critical infrastructure and ensuring collective cyber resilience.
Background
▶ Watch: Introduction: Speakers and open discussion on CVD, CNA, CVE (0:00)
The foundation of robust cybersecurity relies heavily on the timely and accurate dissemination of vulnerability information. At the heart of this process lies Coordinated Vulnerability Disclosure (CVD), a structured approach where a vulnerability discoverer reports a flaw to the affected vendor, allowing them time to develop and release a patch before public disclosure. This mechanism is designed to minimize risk by preventing exploitation during the remediation phase. Complementing CVD is the CVE Program, which assigns unique identifiers (CVE IDs) to publicly known cybersecurity vulnerabilities. These identifiers are issued by CVE Numbering Authorities (CNAs), which can be vendors, security researchers, or national CERTs, forming a distributed network responsible for identifying and describing vulnerabilities.
Despite these established frameworks, the speakers, Reena Rikipi and Tommoito, who co-lead a global CVD community of practice, identified a significant problem: a lack of harmonization in the understanding and implementation of CVD across international partners. Tommoito articulated this core issue, noting that "different members have different image or focus area or focus phase of CVD." This divergence, stemming potentially from cultural differences, language barriers, or varied organizational missions, leads to disparate information quality and fractured disclosure processes, undermining the very goal of effective information exchange.
Historically, the journey towards standardized vulnerability disclosure has been fraught with challenges. Ken Van Wick, formerly of Carnegie Mellon CERT, recounted the early days in 1989 where reporting vulnerabilities often led to legal threats from vendors. This adversarial environment gradually shifted towards a more open and collaborative one, where the "litmus test" for disclosure was whether it made the problem "bigger or smaller." This historical context underscores the progress made but also highlights the persistent need for trust and shared understanding to ensure that disclosures genuinely contribute to risk reduction.
Modern challenges further complicate this landscape. The discussion explored the role of bug bounty programs, with George from Verizon sharing their experience of a costly $2.5 million expenditure in one month due to premature public bug bounties without sufficient internal testing. This illustrates the delicate balance between incentivizing researchers and ensuring organizational maturity. Omar from Cisco emphasized the importance of standards like security.txt and DNS records for clear vulnerability reporting channels. Furthermore, the reliance on centralized platforms, such as CISA's VEX portal, was criticized by Maggie for potentially creating an "America-centrism" that delays information to international partners, prompting calls for more decentralized and direct coordination mechanisms. These multifaceted challenges demonstrate the critical need for the community to come to a common understanding and adopt harmonized practices to build a truly global and effective vulnerability management ecosystem.
Key Findings
▶ Watch: Audience poll: CNAs, aspiring CNAs, and CVE data users (4:00)
The open discussion at VulnCon revealed several critical findings regarding the international challenges in CVD, CNA, and CVE:
- Lack of CVD Harmonization and Shared Understanding: The most prominent finding, articulated by Tommoito, is the significant disparity in how different international partners perceive and practice Coordinated Vulnerability Disclosure (CVD). This lack of a common image or focus area leads to breakdowns in communication, inconsistent information quality, and fragmented disclosure processes, ultimately hindering effective global vulnerability management. Cultural differences, language barriers, and varied organizational missions were identified as contributing factors to this fragmentation.
- Strategic Implementation of Bug Bounty Programs: The conversation highlighted that while bug bounty programs can be valuable, they are not a universal panacea and require a high degree of organizational maturity. Verizon's experience demonstrated the risk of substantial financial losses ($2.5 million in one month) if internal Software Development Life Cycle (SDLC) processes and rigorous testing (e.g., authenticated pentesting, white-box/black-box testing) are not robustly in place before launching public programs. Pete Aller emphasized that bug bounties often become a substitute for internal SDLC, while others argued they offer "thought diversity" and proactive "security in depth" for mature organizations.
- Challenges in International Coordination and "America-centrism": Maggie from Rockwell Automation raised a critical point about perceived "America-centrism" in vulnerability coordination, particularly when using US-centric platforms like CISA's VEX portal. International partners and customers often experience delays in receiving critical vulnerability data, leading to a sense of favoritism and hindering their ability to prepare and translate advisories. This highlights the need for more inclusive and globally distributed coordination mechanisms that respect diverse national CERTs and regional security needs.
- Erosion of Trust and the Need for Decentralized Exchange: Pete Aller and others expressed concerns about the "trust level" being "zilch" with some government-led central disclosure hubs, citing instances where sensitive information was mishandled or over-classified. This led to a strong call for more point-to-point and decentralized information exchange. Thomas from BSI Germany introduced the concept of Voltron, a proposed decentralized protocol stack to manage the CVD state machine and message communication, ensuring participants know the state of disclosure and agree on timelines without a single central authority. Informal, trusted networks like FIRST and Keybase were also cited as effective alternatives for sensitive, real-time data sharing (e.g., TLP Red).
- Evolving Role of Coordinators and CNA Mentorship: The discussion clarified that the role of a CVD coordinator is not always necessary for mature organizations. Thomas (BSI Germany) argued that coordinators should primarily assist inexperienced researchers or companies in their "first run" through CVD, helping them build internal Vulnerability Disclosure Programs (VDPs). Julia Turkovich (CISA) added that CVE Roots often serve as mentors, guiding new CNAs to achieve organizational maturity, rather than simply assigning CVE IDs. This suggests a shift towards empowering organizations to manage their own disclosures, with coordinators stepping in for complex multi-party cases.
- Quality over Quantity in the CVE Program: Pete Aller, a CVE Board member, strongly argued against the notion that every organization needs to become a CNA, especially if they only issue one CVE every few years. He emphasized that the focus should be on the quality and impact of vulnerability information, not just the number of CNAs. The goal is to ensure that information is "accepted and actioned" by customers, requiring better communication and a collective understanding of risk.
- Machine Readability as a Key Enabler: Thomas (BSI Germany) stressed the critical importance of machine-readable advisories, specifically mentioning CSAF (Common Security Advisory Framework). He argued that automated processing of vulnerability data in formats like CSAF is essential for efficient analysis, allowing customers to integrate information directly into their systems "in a blink" without manual intervention or media breaks. This is seen as a way to reduce reliance on pre-disclosure groups and make public disclosure more effective.
These findings collectively point towards a future of vulnerability management that is more decentralized, trust-based, technologically advanced, and focused on empowering participants while ensuring global reach and consistent quality.
Technical Deep Dive
▶ Watch: Introducing the core problem statement for the discussion (5:00)
The discussion, while open-ended, touched upon several critical technical aspects and protocols underpinning effective vulnerability management and disclosure. The core problem statement revolved around the disparate understanding of Coordinated Vulnerability Disclosure (CVD), a multi-stage process involving vulnerability discovery, reporting, validation, remediation, and public communication.
A central theme was the role of CVE Numbering Authorities (CNAs) within the CVE Program. CNAs are organizations authorized to assign CVE IDs to vulnerabilities. The discussion highlighted that while the program is designed to create a distributed network for vulnerability identification, the quality and consistency of the information produced by CNAs, as well as their understanding of CVD, vary significantly. Pete Aller, a CVE board member, critiqued the notion that every entity needs to be a CNA, particularly if they only issue a few CVEs over several years, advocating for a focus on quality and effective action by consumers rather than mere quantity of CNAs.
The implementation of bug bounty programs also led to a technical exchange. George from Verizon detailed a maturity model for their bug bounty program: starting with authenticated penetration testing against non-production environments (internal or third-party), followed by Pentest-as-a-Service from a production black-box perspective, then private bug bounties, and finally, only for very mature applications, public bug bounties. This layered approach aims to prevent the exorbitant costs ($2.5 million in one month) associated with premature public bounties on untested applications. Omar from Cisco elaborated on robust reporting mechanisms, advocating for the adoption of security.txt files and DNS records to standardize how security researchers can find vulnerability reporting channels. He also distinguished between paid bug bounty programs and Vulnerability Disclosure Programs (VDPs) that do not offer financial compensation, noting that Cisco utilizes both.
A significant technical innovation discussed was Voltron, a proposed decentralized protocol stack being developed at BSI Germany, mentioned by Thomas. Voltron aims to create a state machine for CVD, allowing participants in the ecosystem to track the progress of a vulnerability disclosure case, know "in which state everyone is," and "agree on the disclosure date." This protocol is designed to facilitate communication messages within this state machine, addressing the need for better coordination without relying on a single, centralized platform.
The concept of machine-readable advisories was heavily emphasized as a solution to current information exchange inefficiencies. Thomas highlighted the importance of CSAF (Common Security Advisory Framework), formerly CVRF (Common Vulnerability Reporting Framework). CSAF enables automated ingestion and processing of vulnerability information by security tools and systems, allowing organizations to "evaluate that in a blink" and integrate it into their systems without manual "media breaks." This contrasts with the current reliance on human analysts manually extracting information from vendor websites, which is slow and error-prone. The goal is to make public disclosure as effective as pre-disclosure, especially for critical infrastructure, by ensuring that the information is immediately actionable through automated means (e.g., pushing out Snort rules or other defensive measures).
The discussion also implicitly touched upon vulnerability metrics like CVSS (Common Vulnerability Scoring System), which is widely used to assess vulnerability severity, and the Known Exploited Vulnerabilities (KEV) Catalog from CISA, which lists vulnerabilities actively exploited in the wild. Brian Ford, a technical educator, noted that these tools (CVE, NVD, CVSS, KEV) are standard in cybersecurity curricula, but emphasized the need to teach students more about diverse CNA examples and responsible disclosure practices beyond just the major vendors.
Finally, the concept of TLP (Traffic Light Protocol) Red was mentioned by Pete Aller in the context of informal, trusted networks. TLP Red signifies information that is highly restricted and intended for named recipients only, not to be disclosed further. This illustrates the need for flexible, trust-based communication channels for extremely sensitive vulnerability data, especially when formal systems might be perceived as too slow or unreliable. The overall technical trajectory points towards automation, decentralization, and standardization to overcome the current fragmentation in global vulnerability coordination.
Demo / Proof of Concept
▶ Watch: First audience question: CVD case failures due to miscommunication (7:40)
This session was structured as an open discussion rather than a presentation featuring specific technical demonstrations or proofs of concept. The speakers facilitated a collaborative dialogue with the audience, drawing on collective experiences and challenges related to Coordinated Vulnerability Disclosure (CVD), CVE Numbering Authorities (CNAs), and CVE data consumption. As such, no live demos, code examples, or technical PoCs were presented during the talk. The focus was entirely on identifying and discussing the systemic issues and potential strategic approaches to improve the global vulnerability ecosystem.
Defensive Implications
▶ Watch: Verizon's perspective: Receiving vulnerability reports, not a CNA (8:00)
The detailed discussion on international challenges in CVD, CNA, and CVE has profound implications for defenders across various organizational types. Adopting the insights from this talk can significantly enhance an organization's proactive and reactive security posture.
For Vendors and Software Producers:
- Harmonize Internal CVD Processes: Vendors must ensure a consistent and clear understanding of Coordinated Vulnerability Disclosure (CVD) across all internal teams and with external partners. This includes establishing robust Vulnerability Disclosure Programs (VDPs) with clear reporting channels, potentially leveraging standards like
security.txtand DNS records for discoverability. - Elevate SDLC Maturity Before Bug Bounties: Organizations should prioritize investment in a mature Software Development Life Cycle (SDLC), including comprehensive internal testing (authenticated pentesting, white-box/black-box testing, source code review, DAST). Public bug bounty programs should be considered a complement for high-priority products, offering "thought diversity" after extensive internal vetting, rather than a primary testing mechanism to avoid costly mistakes (like Verizon's $2.5 million experience).
- Embrace Machine-Readable Advisories: To facilitate rapid consumption and action by customers, vendors should publish their vulnerability advisories in machine-readable formats like CSAF (Common Security Advisory Framework). This allows customers to automate the ingestion and analysis of vulnerability data, reducing manual effort and speeding up remediation cycles.
- Strategic Engagement with Coordinators: While mature vendors should manage most disclosures independently, engaging with CVD coordinators (like CISA or JPCERT/CC) is beneficial for complex multi-party vulnerabilities or when facing novel disclosure challenges. Coordinators can offer guidance and facilitate broader coordination when internal capacity is limited.
- Consider CNA Status Judiciously: Becoming a CVE Numbering Authority (CNA) should be a strategic decision for vendors that consistently discover and disclose vulnerabilities. Organizations that rarely issue CVEs might be better served by obtaining CVEs from existing CNAs, allowing them to focus resources on core security functions and high-quality disclosures rather than administrative overhead.
For Consumers and Organizations Operating Systems:
- Prioritize Risk, Not Just Compliance: Defenders should move beyond a "check-mark" mentality driven solely by vulnerability scanner outputs. Instead, focus on understanding the actual risk posed by vulnerabilities to their specific environment, considering factors like exploitability, impact, and the presence of Known Exploited Vulnerabilities (KEVs). This requires deeper analysis than just applying every patch without context.
- Demand CSAF Advisories: Encourage vendors to provide vulnerability advisories in CSAF format. This enables automated integration of vulnerability data into internal security tools, such as vulnerability management systems, SIEMs, and SOAR platforms, drastically improving triage and response times.
- Cultivate Trusted Information Exchange Networks: Actively participate in informal and formal cybersecurity communities like FIRST (Forum of Incident Response and Security Teams), IIcazi (now folding into PISIG), and other trusted groups (e.g., Keybase for TLP Red exchanges). These networks provide timely, context-rich vulnerability intelligence that may not be available through formal channels, especially for critical infrastructure.
- Prepare for Decentralized Coordination: Be aware of emerging decentralized protocols like Voltron that aim to streamline multi-party CVD. Understanding these approaches will be crucial for participating in future, more efficient coordination efforts.
- Educate Leadership on CVD: Proactively educate corporate leadership on the nuances of vulnerability disclosure, including the importance of collaboration over confrontation (avoiding knee-jerk legal threats) and the value of transparent, timely information sharing. This fosters a culture that views vulnerability reports as opportunities for improvement rather than threats.
For Coordinators and Government Agencies (CISA, JPCERT/CC, BSI):
- Focus on Mentorship and Upskilling: Continue to serve as mentors for inexperienced organizations and researchers, guiding them in establishing mature VDPs and effective CVD practices. This includes supporting CVE Roots in their role of fostering new CNAs.
- Promote Decentralized and Inclusive Platforms: Actively explore and support the development and adoption of decentralized protocols like Voltron to overcome the limitations of centralized, national-centric coordination platforms. This will facilitate more equitable and efficient international information sharing, addressing concerns about "America-centrism."
- Advocate for Quality and Consistency: Prioritize the quality and actionable nature of vulnerability information over the sheer number of CNAs. Work towards harmonizing CVD processes and promoting best practices that lead to effective risk reduction for end-users.
- Integrate Responsible Disclosure into Education: Collaborate with technical educators (like Brian Ford) to embed comprehensive lessons on responsible disclosure, diverse CNA examples, community engagement, and the practical application of standards (e.g., CSAF,
security.txt) into cybersecurity curricula. This will prepare the next generation of professionals for the complex realities of the vulnerability ecosystem.
By implementing these defensive implications, the cybersecurity community can collectively move towards a more resilient, collaborative, and effective global approach to managing software vulnerabilities.
Key Takeaways
- CVD Harmonization is Critical: The global cybersecurity community suffers from a fragmented understanding and inconsistent practice of Coordinated Vulnerability Disclosure (CVD). Harmonizing these processes across international partners is essential to ensure effective, high-quality information flow and reduce global risk.
- Bug Bounties Require Maturity: Bug bounty programs are not a substitute for robust internal Software Development Life Cycle (SDLC) testing. Organizations must achieve significant internal security maturity before engaging in public bug bounties to avoid substantial costs and maximize their effectiveness as a "security in depth" measure.
- Decentralization and Trust are Paramount: Over-reliance on centralized government-led disclosure platforms can lead to delays, perceived favoritism, and erode trust. Future CVD must move towards more decentralized protocols (like the proposed Voltron) and leverage trusted, point-to-point informal networks (e.g., FIRST, Keybase) for sensitive, timely information exchange.
- Machine-Readable Advisories are a Game-Changer: The adoption of machine-readable advisory formats like CSAF (Common Security Advisory Framework) is crucial for automating the ingestion, analysis, and actioning of vulnerability information. This will significantly improve the speed and efficiency of defensive responses for all stakeholders.
- Coordinator Role is Evolving: The role of CVD coordinators and CVE Roots should primarily focus on mentoring inexperienced organizations and facilitating complex, multi-party disclosures. Mature vendors should be empowered to manage their own disclosures, with a focus on contributing high-quality, actionable vulnerability data to the ecosystem.
- Educate the Next Generation: Cybersecurity education must expand beyond basic CVE, NVD, and CVSS concepts to include comprehensive training on diverse CNA practices, the nuances of responsible disclosure, the importance of community engagement, and the adoption of modern standards and decentralized approaches.
About the Speaker(s)
Reena Rikipi works for CISA, the Cybersecurity and Infrastructure Security Agency, where she leads strategic partnerships and vulnerability program development. Her background includes extensive experience in writing joint cyber advisories and publishing a series of "secure by design alerts" focused on eliminating classes of vulnerabilities, reflecting her passion for proactive security. At CISA, she actively supports efforts in recruiting and upskilling CNAs, contributes to improvements within the CVE program, and co-leads the global CVD community of practice alongside Tommoito.
Tommoito is from the JPCERT Coordination Center (JPCERT/CC), where he serves as a CVD coordinator. His work primarily focuses on key areas such as CVD, CVE, and SBOM (Software Bill of Materials). He is deeply involved in all aspects related to CVD and is a co-leader of the global CVD community of practice, working to foster common ground and address challenges in coordinated vulnerability disclosure across international partners.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A panel-style open discussion at VulnCon on international CVD coordination challenges. This is firmly in the policy/process lane, not technical research, and should be judged accordingly. The session surfaces real friction points — CVD harmonization gaps across national CERTs, the 'America-centrism' critique of US-centric disclosure platforms, the Voltron decentralized protocol concept, and the CSAF machine-readability push — and the format of letting practitioners argue it out openly is appropriate for the subject matter. The problem is that most of what's said here has been circulating in CVD-adjacent circles for years, and while the conversation is honest and occasionally sharp, it…
Heather Calloway (CISO) — SOLID
A useful practitioner forum on real friction in the global vulnerability disclosure ecosystem — CVD harmonization gaps, CNA quality over quantity, CSAF adoption, and the trust deficit with centralized coordination platforms. The discussion surfaces genuine institutional dysfunction that affects every organization running a vulnerability management program. But it stays at the level of community conversation rather than producing clear decisions or concrete accountability. The Voltron concept and the CSAF push are worth tracking. The rest is diagnosis without a verdict.