CVSS: NIST restricts the assessment of IT security vulnerabilities
Summary
NIST will largely stop routinely assigning CVSS severity scores to vulnerabilities in the National Vulnerability Database. The agency wants to reduce the backlog of vulnerability analyses, cut costs, and improve processing speed. The article also highlights broader issues around underfunding, staffing gaps, and overlapping work with CISA’s Vulnrichment project. Security teams and software vendors should watch this change closely because it may affect how they prioritize vulnerabilities and how they submit or consume vulnerability data.
Classifications
industries
No industries detected
applications
No applications detected
AskAI Classifications
Labels
No AI classifications detected