On 16 April, the cybersecurity community was startled by the announcement about the MITRE organization: Funding for the CVE and CWE programs is coming to an end, and with it the continued existence of the CVE database. In particular, the Common Vulnerabilities and Exposures program, which ensures a globally unique designation of vulnerabilities, is essential for the fast and effective elimination of security vulnerabilities in OT systems.

Even if funding is currently secured for at least the next eleven months, the question remains: How reliable and available is the information on vulnerabilities in IT and OT systems? In particular, the question should be asked as to whether relying on a single central instance on an insecure foundation is a good basis for the security of one's own critical infrastructure.

Fortunately, several alternatives emerged on the same day. ENSIA has also put its EU Vulnerability Database online. This database is currently still in a beta stage. This database ensures the availability of vulnerability information for the future, but does not reduce the complexity faced by IT and OT security managers.

Vulnerability management and threat intelligence tools can significantly reduce this complexity. By using various sources of information, including the security advisories provided directly by the manufacturers, up-to-date and detailed information can be provided not only on the vulnerabilities, but also on their criticality and the countermeasures.

The StationGuard solution uses this processed information in GridOps together with an automatically generated asset inventory, which records the detailed data on the existing OT systems. By precisely assigning the asset data to the security advisories, only the vulnerabilities relevant to your own OT infrastructure are listed, including countermeasures. This dramatically reduces the effort required for vulnerability management. The patching of OT systems can then be prioritized and optimized based on the criticality of the existing vulnerabilities.The StationGuard solution works independently of the CVE database and other services such as the NVD.
 

Resources