VEX

Vulnerability Exploitability eXchange

VEX is a machine-readable format with which a manufacturer communicates whether a product is actually affected by and exploitable through a particular vulnerability — or not. It is the most important complement to the Software Bill of Materials (SBOM) because it reduces the flood of potential hits to the truly relevant ones. It answers the question „Does this even affect me?“.

History & facts. An Software Bill of Materials (SBOM) shows that a vulnerable component is contained — but not whether the vulnerability is reachable or exploitable at all in the concrete product. VEX closes exactly this gap: the manufacturer states a status per vulnerability, typically „not affected“, „affected“, „fixed“ or „under investigation“, often with justification. The concept is driven by the United States of America (US) agency Cybersecurity and Infrastructure Security Agency (USA) (CISA) in the environment of SBOM work; widespread implementations are Common Security Advisory Framework (CSAF) VEX (based on the OASIS standard CSAF), CycloneDX VEX and OpenVEX.

Outlook & recommendation. Without VEX, Software Bill of Materials (SBOM)-based scanning quickly leads to alert fatigue because many reported vulnerabilities are not exploitable at all in the concrete deployment. VEX makes vulnerability management efficient by directing attention to the essentials — especially valuable when tight deadlines must be met under the Cyber Resilience Act (CRA) and Network and Information Security Directive 2 (NIS2). It is advisable to operate SBOM and VEX together and to feed both, automatically, into one's own vulnerability and threat data processing.

VEX — Vulnerability Exploitability eXchange