Solved

How often are update CVEs?

  • 24 August 2023
  • 4 replies
  • 564 views

Userlevel 2
Badge

Agent

N/A

Platform

Current

Cloud

N/A

icon

Best answer by juliensobrier 25 August 2023, 18:30

View original

4 replies

Userlevel 2
Badge

Lacework ingests new CVEs daily from OS vendors and the NIST National Vulnerability Database (NVD).

Userlevel 1
Badge

We update our CVE database daily. However, for major new vulernabiliies (such as Log4j), we can update it multiple times a day.

Badge

Additional sub-question: Do we notate zero-day vulnerabilities any differently?

By definition, zero-days don’t have a CVE before they are disclosed. We will alert based on behavior, but not in the vulnerability section.

 

We do note whether vulns have a published exploit and use that as part of the risk scoring.

Reply