cvevulnerabilityai-securityvulnerability-management

ThreatDown - The Mystery of CVEs That Are Not Vulnerabilities

Warns of the decreasing reliability of vulnerability databases due to automated bots filing bogus CVE reports from old resolved bugs.

Summary

The CVE database is increasingly targeted by automated bots and AI tools that scrape old issues and commits to file bogus or irrelevant vulnerability records without maintainer involvement. A recent surge saw 138 new 'vulnerabilities' entered into open-source projects on a single day, including a 2019 curl bug (CVE-2020-19909) that was incorrectly categorized as a new critical integer overflow years after it was fixed. These automated submissions create significant noise for security teams, as many scanners disregard the 'DISPUTED' status, wasting triage resources on non-issues while actual vulnerabilities remain unaddressed.

Gaps Analysis

Evidence

Filing vulnerabilities that are in fact bugs that were resolved long ago is a weird form of fear mongering... scanners will not see or disregard the 'DISPUTED' status.

Blind Spot

Risk Guard trusts CVE status but does not currently account for 'Disputed' flags or the historical accuracy of a CVE reporter.

Actionable Capability

Risk Guard would be better if it verified the 'Disputed' status of CVEs and factored in maintainer feedback to reduce false positives from automated reporting bots.

← Previous Next →