Glossary · OT cybersecurity
Common Vulnerabilities and Exposures (CVE)
Also known as: CVE ID, CVE identifier
German: Common Vulnerabilities and Exposures (CVE)
Common Vulnerabilities and Exposures (CVE) is a public program that assigns unique identifiers such as CVE-2024-12345 to publicly disclosed cybersecurity vulnerabilities, so that vendors, operators and tools can refer to the same vulnerability unambiguously. Identifiers are assigned by CVE Numbering Authorities.
- OT security
In one sentence
CVE assigns unique public identifiers to disclosed cybersecurity vulnerabilities so vendors, operators and tools refer to the same issue.
Example
A vendor security advisory for an HMI panel lists two CVE IDs, which the plant's vulnerability scanner uses to flag affected devices in the asset inventory.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
How it applies
- Engineering: Product suppliers that are CVE Numbering Authorities, or work with one, request CVE IDs when they publish vulnerabilities in their products. Many industrial automation vendors publish CVEs through their product security teams.
- Operation: Operators match CVE entries against their Asset inventory and Software bill of materials (SBOM) to find affected systems. A CVE record identifies the vulnerability; it does not by itself say how urgent it is for a given plant.
- Maintenance: CVE IDs connect advisories, patches, scanner findings and tickets, which makes Vulnerability management traceable.
- Documentation: Release notes should list the CVE IDs fixed in each firmware or software version, so that customers can document why an update was installed. Security advisories should use the CVE ID consistently in title and body.
CVE vs. CVSS
CVE names a vulnerability. Common Vulnerability Scoring System (CVSS) rates its severity. A CVE record often carries a CVSS score, but the two are separate systems.