CNA
CVE Numbering Authority
CVE-Vergabestelle
A CNA is an entity authorised by the Common Vulnerabilities and Exposures (CVE) programme to independently assign CVE-IDs within its defined scope — for instance a vendor for its own products. This decentralised model spreads the burden of vulnerability cataloguing across many shoulders. It is the organisational backbone behind the seemingly simple CVE number.
History & facts. Initially only MITRE assigned Common Vulnerabilities and Exposures (CVE)-IDs, which did not scale with the growing number of vulnerabilities. The CNA model delegates assignment to vendors, research institutions, CERTs and coordination bodies, each responsible for a delimited scope. A vendor can thus often assign an ID to a flaw in its product directly, coordinated with the actual disclosure.
Outlook & recommendation. The quality of Common Vulnerabilities and Exposures (CVE) records depends directly on the respective CNA — depth of description, product details and timing vary. For one's own vulnerability management it helps to know which CNA is responsible for a deployed product, since its advisory is often more precise than the bare National Vulnerability Database (USA) (NVD) entry. The decentralised model also makes the overall system more robust against the failure of a single body.