NVD - Products You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://nvd.nist.gov An official website of the United States government Here's how you know Official websites use .gov A .gov website belongs…
NVD - Products You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://nvd.nist.gov An official website of the United States government Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. NVD MENU General Expand or Collapse NVD Dashboard News and Status Updates FAQ Visualizations Legal Disclaimer Vulnerabilities Expand or Collapse Search & Statistics Weakness Types Data Feeds Vendor Comments CVMAP Vulnerability Metrics Expand or Collapse CVSS v4.0 Calculators CVSS v3.x Calculators CVSS v2.0 Calculator Products Expand or Collapse CPE Dictionary CPE Search CPE Statistics SWID Developers Expand or Collapse Start Here Request an API Key Vulnerabilities Products Data Sources Terms of Use Contact NVD Other Sites Expand or Collapse Checklist (NCP) Repository Configurations (CCE) 800-53 Controls SCAP Search Expand or Collapse Vulnerability Search CPE Search Information Technology Laboratory National Vulnerability Database National Vulnerability Database NVD General Expand or Collapse NVD Dashboard News and Status Updates FAQ Visualizations Legal Disclaimer Vulnerabilities Expand or Collapse Search & Statistics Weakness Types Data Feeds Vendor Comments CVMAP Vulnerability Metrics Expand or Collapse CVSS v4.0 Calculator CVSS v3.x Calculators CVSS v2.0 Calculator Products Expand or Collapse CPE Dictionary CPE Search CPE Statistics SWID Developers Expand or Collapse Start Here Request an API Key Vulnerabilities Products Data Sources Terms of Use Contact NVD Other Sites Expand or Collapse Checklist (NCP) Repository Configurations (CCE) 800-53 Controls SCAP Search Expand or Collapse Vulnerability Search CPE Search Product Identification A fundamental part of the CVE enrichment process is to uniquely identify the vulnerable products affected by any given vulnerability. This effort allows consumers of our data to check for known issues for any product they may currently have in their environment (as long as they know the associated product identifier). The NVD currently uses the CPE 2.3 specifications to accomplish this goal. CPE is a structured naming scheme for information technology systems, software, and packages. Based upon the generic syntax for Uniform Resource Identifiers (URI), CPE includes a formal name format, a method for checking names against a system, and a description format for binding text and tests to a name. For more information regarding CPE and its uses, please refer to the NVD CPE products page. NVD enrichment team members assign applicability statements consisting of CPE match strings to CVEs during the enrichment process. These match strings are intended to correlate with CPEs present in the official CPE Dictionary. In the event a CPE does not exist in the CPE Dictionary, NVD staff will submit a request to have them added. The NVD is always looking to improve on the methodologies it uses. As such SWID is being looked into as a possible replacement for CPE. SWID (Software Identification) Tags are a software product identification specification. SWID tags support automation of software inventory as part of a software asset management (SAM) process, assessment of software vulnerabilities present on a computing device, detection of missing patches, targeting of configuration checklist assessments, software integrity checking, installation and execution allowlists/denylists, and other security and operational use cases. For more information on SWID please refer to the SWID information page. X (link is external) facebook (link is external) linkedin (link is external) youtube (link is external) rss govdelivery (link is external) HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 (301) 975-2000 Webmaster | Contact Us | Our Other Offices Incident Response Assistance and Non-NVD Related Technical Cyber Security Questions: US-CERT Security Operations Center Email: [emailprotected] Phone: 1-888-282-0870 Site Privacy | Accessibility | Privacy Program | Copyrights | Vulnerability Disclosure | No Fear Act Policy | FOIA | Environmental Policy | Scientific Integrity | Information Quality Standards | Commerce.gov | Science.gov | USA.gov