Also this raises the point of "CVE's are for public vulnerabilities" but should we maybe look at what public means/how it is defined (I imagine the DoD/related community would benefit from CVE, but not always be in a position to make the CVEs they assign truly public). Maybe a separate namespace/number space for this kind of thing? (ala IPv4 space 10.*, 172.16.* and so on).
--