Demystifying the CVE Ecosystem: Community-Perceived Impacts and Problems
Yiliang Zhao, Hengzhi Ye, Minghui Zhou, Huaimin Wang
摘要
The Common Vulnerabilities and Exposures (CVE) system plays a critical role in global cybersecurity by standardizing the identification and cataloging of software and hardware vulnerabilities. However, recent high-profile incidents highlight the potential pitfall of the system, indicating the space for improvement. Despite significant interests in and substantial studies on CVE system, there is a lack of understanding to what extent the participants are impacted, and what problems are exactly in the CVE ecosystem. To bridge the knowledge gap, we extensively collect blog posts, community discussions, and editorial articles from various sources, including Reddit, LWN.net, and GitHub, and employ a thematic analysis approach to identify the perceived adverse impact on participants as well as the inherent problems within the CVE ecosystem. Then we conducted a community survey with 77 participants for verification. The results unveil the impacts on various participants within the prevailing CVE ecosystem and for the first time comprehensively trace and elucidate the problems that may cause these impacts. Based on the findings and survey results, we propose a series of implications to mitigate existing problems within the CVE ecosystem, aiming to enhance its efficiency and health.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Confusing Value with Enumeration: Studying the Use of CVEs in AcademiaMoritz Schloegel, Daniel Klischies, Simon Koch, David Klein 等USENIX Security 2025
- Shedding Light on CVSS Scoring Inconsistencies: A User-Centric Study on Evaluating Widespread Security VulnerabilitiesJulia Wunder, Andreas Kurtz, Christian Eichenmüller, Freya Gassmann 等S&P 2024 · 被引用 25 次
- A Grounded Theory Based Approach to Characterize Software Attack SurfacesSara Moshtari, Ahmet Okutan, Mehdi MirakhorliICSE 2022 · 被引用 7 次
- A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security FeaturesJessy Ayala, Yu-Jye Tung, Joshua GarciaUSENIX Security 2025
- Between Risk, Recognition, and Necessity: How Open-Source Project Maintainers Perceive and Navigate CVEs Through Reporting and Resolving VulnerabilitiesJessy Ayala, Steven Ngo, Joshua GarciaCCS 2026
