|
|
Can someone give a few examples of a service vulnerability?
Regards,
Beverly M Finch, PMP
PSIRT Program Manager
Product Security Office
7001 Development Drive
Office 3N-C1
Morrisville, NC 27560
+1 919 294 5873
beverlyfinch@lenovo.com
Lenovo.com
Twitter | Facebook |Instagram | Blogs | Forums
-----Original Message-----
From: owner-cve-editorial-board-list@lists.mitre.org [mailto:owner-cve-editorial-board-list@lists.mitre.org ] On Behalf Of Art Manion
Sent: Wednesday, September 6, 2017 9:53 AM
To: Millar, Thomas; Andy Balinsky (balinsky); kseifried@redhat.com
Cc: cve-editorial-board-list
Subject: Re: CVE For Services
On 2017-09-06 09:35, Millar, Thomas wrote:
> 4. Plus whatever we said 6 months ago; I'm in transit so the archives are not readily accessible
My recollection, human memory being what it is, was that it would be permissible to assign CVE IDs to service vulnerabilities, but that we didn't expect anything near comprehensive coverage, for reasons in this thread and others. Also we didn't expect CVE or other CNAs to make a concerted effort to track service vulnerabilities (although, we didn't finish the bug bounty provider discussion).
About the legality of testing services: While interesting, not directly CVE's problem. Confirmation/evidence collection of service vulnerabilities will be much harder.
- Art