Post from 2024-11-24 19:25:09

@screaminggoat @dreadpir8robots @todb @h4sh IME CVE issuance is the easiest part: if vendor is a CNA, they will take care of it, most of the process is coordinating technical details and disclosure. If it's MITRE you can get a CVE basically instantly with their online form.

I have to note that AFAIK MITRE is *not* a fallback (they will redirect you to the CNA you just visited), and H1 is *definitely* not a fallback (for a multitude of reasons). FD is a fallback, and so is CERT-CC in some cases.
permalink | main