I'm not clear, the CVE ID, was it assigned because people are NOT supposed to be able to upgrade or something?
By this logic every vendor would need a CVE ID for every software package that can be updated to a version that has a flaw introduced in a later version (so like uhh.. all of them basically).