

S6E11: Josh Bressers & Dan Lorenc - Untangling the NVD Chaos
Mar 22, 2024
Experts discuss the drama around NVD and its impact on vulnerability management. They highlight concerns about lack of CVE enrichment and the grassroots effort to raise awareness. The podcast explores the underfunding and oversight of critical software ecosystem components. Future solutions from NIST/NVD, government, and industry are discussed to resolve the issue.
Chapters
Transcript
Episode notes
1 2 3 4 5
Introduction
00:00 • 2min
Challenges of NVD Data Enrichment and Vulnerability Management
02:05 • 16min
Exploring CPE Criticisms, Pearl Usage, and Government Involvement in Software Management
17:44 • 3min
Anticipation and Skepticism Regarding NVD Announcement at Volcan Conference
20:26 • 2min
Navigating the Complexity of Software Vulnerability Databases
22:01 • 7min