Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

CSAF and CVE Record list different affected versions for same advisory

Дата публикации: 05-10-2026 08:27:04

Hello,I am comparing the affected version lists published by Cisco in two formats forthe same advisory, and I consistently find a difference. I would like tounderstand whether this is expected.== Example 1: cisco-sa-asa-ftd-ios-dos-kPEpQGGK / CVE-2026-20012 ==CSAF (product_status.known_affected, relationships expanded) : 1,429 versionsCVE Record (containers.cna.affected[].versions) : 1,271 versionsVersions present in CSAF but not in the CVE Record : 158The CVE Record is a strict subset of the CSAF. The difference is not caused bynotation (normalising parentheses, dots and leading zeros resolves none of them),and both documents were published on 2026-03-25, three minutes apart.The difference is limited to two product lines:IOS 647 in CSAF, 94 missing (14.5%)Cisco IOS XE Software 442 in CSAF, 64 missing (14.5%)Secure Firewall ASA 235 in CSAF, 0 missing (0%)Secure Firewall FTD 105 in CSAF, 0 missing (0%)I checked whether the missing versions are simply unknown to Cisco. They are not.Querying the openVuln APIGET /security/advisories/v2/OSType/{ios|iosxe}?version={version}returns HTTP 200 for 131 of the 132 missing versions I tested, and every one ofthose responses includes this advisory. Two thirds of them also return afirstFixed value, so a fixed release exists.Entire trains are absent from the CVE Record while being fully present in CSAF,for example 15.4(3)M (all 13 versions) and IOS XE 3.10.xS (all 16 versions).== Example 2: cisco-sa-ios-xmcp-thbAr34t / CVE-2026-20301 ==CSAF (snapshot taken the day after publication) : 541 versionsCVE Record : 427 versionsMissing : 114Here the excluded set is different. Trains such as 15.3(3)M, 15.5(3)M, 15.6(3)M,15.5(3)S and 15.4(3)S are completely absent from this CVE Record, although thesame trains are present in the CVE Record for CVE-2026-20012 published fivemonths earlier.== Questions ==1. Is this difference expected and documented somewhere?2. For the operating systems supported by Cisco Software Checker, which sourceshould be treated as authoritative for affected versions - the CSAF, or theCVE Record?3. Consumers that rely on the CVE Record or on NVD will not match a devicerunning, for example, 15.4(3)M5, even though Software Checker reports it asaffected. Is there any plan to align the two outputs?Thank you.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Re: How to step update version asa firepower 1140011.7705-10-2026
2Какие наши продукты задевает эта CVE? Я продолжил заброшенный Minefield и нашёл, что он читал SBOM задом наперёд0926-09-2026
3WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV09.7125-09-2026
4Re: ISE 3.3 Patc 5- user cannot change password if expire05.9605-10-2026
5Re: ISE 3.3 Patc 5- user cannot change password if expire019.0105-10-2026
6Re: How to step update version asa firepower 114008.8205-10-2026
7Navigating Cyber Disclosures in 2026: A Limited Renewal of CISA 2015, and “Take Two” on Finalizing CIRCIA’s Reporting Regulations011.7426-02-2026
8Re: ISE 3.3 Patc 5- user cannot change password if expire022.2405-10-2026
9CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally07.6328-09-2026
10Re: EoMPLS VC Type 4 and VC Type 508.8905-10-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 7.78. Источник: community.cisco.com.