Which database is the U.S. government repository that provides CVE details and vulnerability scores?

Prepare for the Certified Ethical Hacker Version 11 Exam. Study with comprehensive questions and explanations. Equip yourself with the skills needed for success!

Multiple Choice

Which database is the U.S. government repository that provides CVE details and vulnerability scores?

Explanation:
The National Vulnerability Database is the U.S. government repository for CVE details and vulnerability scores. It hosts CVE entries—the identifiers and descriptions assigned by MITRE—and augments them with CVSS-based severity scores, impact metrics, and related metadata. This combination makes it the authoritative source for both the vulnerability descriptions and their standardized risk ratings in a government-supported, publicly accessible database. The CVE itself is just the naming system for vulnerabilities, not a scoring database. OSVDB was a separate project that is no longer maintained, and CWE classifies software weaknesses rather than individual vulnerabilities or scores.

The National Vulnerability Database is the U.S. government repository for CVE details and vulnerability scores. It hosts CVE entries—the identifiers and descriptions assigned by MITRE—and augments them with CVSS-based severity scores, impact metrics, and related metadata. This combination makes it the authoritative source for both the vulnerability descriptions and their standardized risk ratings in a government-supported, publicly accessible database. The CVE itself is just the naming system for vulnerabilities, not a scoring database. OSVDB was a separate project that is no longer maintained, and CWE classifies software weaknesses rather than individual vulnerabilities or scores.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy