Demystifying the CVE Ecosystem: Community-Perceived Impacts and Problems
The Common Vulnerabilities and Exposures (CVE) system plays a critical role in global cybersecurity by standardizing the identification and cataloging of software and hardware vulnerabilities. However, recent high-profile incidents highlight the potential pitfall of the system, indicating the space for improvement. Despite significant interests in and substantial studies on CVE system, there is a lack of understanding to what extent the participants are impacted, and what problems are exactly in the CVE ecosystem. To bridge the knowledge gap, we extensively collect blog posts, community discussions and editorial articles from various sources including Reddit, LWN.net and GitHub, and employ thematic analysis approach to identify the perceived adverse impact on participants as well as the inherent problems within the CVE ecosystem. Then we conducted a follow-up community survey with 77 participants for validation. The results unveil the impacts on various participants within the prevailing CVE ecosystem and for the first time comprehensively trace and elucidate the problems that may cause these impacts. Based on the findings and survey results, we propose a series of implications to mitigate existing problems within the CVE ecosystem, aiming to enhance its efficiency and health.