From 9900a11e74fa79e5805c930dcabdaf0b618c524c Mon Sep 17 00:00:00 2001
From: Robert Roberge
Date: Tue, 19 Nov 2024 10:16:28 -0500
Subject: [PATCH] #3272 CNA Enrichment Recognition List for 11/18/24 (#3275)
(#3276)
---
src/assets/data/news.json | 30 ++++++++++++++++++++++++++++++
src/views/About/Metrics.vue | 16 +++++++++-------
2 files changed, 39 insertions(+), 7 deletions(-)
diff --git a/src/assets/data/news.json b/src/assets/data/news.json
index bfe2392e..c794fe21 100644
--- a/src/assets/data/news.json
+++ b/src/assets/data/news.json
@@ -1,5 +1,35 @@
{
"currentNews": [
+ {
+ "id": 441,
+ "newsType": "blog",
+ "title": "Vulnerability Data Enrichment for CVE Records: 224 CNAs on the Enrichment Recognition List for November 18, 2024",
+ "urlKeywords": "CNA Enrichment Recognition List Update",
+ "date": "2024-11-19",
+ "author": {
+ "name": "CVE Program",
+ "organization": {
+ "name": "CVE Program",
+ "url": ""
+ },
+ "title": "",
+ "bio": ""
+ },
+ "description": [
+ {
+ "contentnewsType": "paragraph",
+ "content": "The “CNA Enrichment Recognition List” for November 18, 2024, is now available with 224 CNAs listed. Published every two weeks on the CVE website, the list recognizes those CVE Numbering Authorities (CNAs) that are actively providing enhanced vulnerability data in their CVE Records. CNAs are added to the list if they provide Common Vulnerability Scoring System (CVSS) and Common Weakness Enumeration (CWE™) information 98% of the time or more within the two-week period of their last published CVE Record."
+ },
+ {
+ "contentnewsType": "paragraph",
+ "content": "For more about the recognition list, see “Recognition for CNAs Actively Providing Vulnerability Data Enrichment for CVE Records.” To learn more about vulnerability information types like CVSS and CWE, see the CVE Record User Guide. View the most current CNA Enrichment Recognition List on the CVE website Metrics page here."
+ },
+ {
+ "contentnewsType": "paragraph",
+ "content": "CNA Enrichment Recognition List for November 18, 2024, with 224 CNAs listed:
9front Systems
Absolute Software
Acronis International GmbH
Adobe Systems Incorporated
Advanced Micro Devices Inc.
AlgoSec
Amazon
AMI
AppCheck Ltd.
Arista Networks, Inc.
Asea Brown Boveri Ltd.
ASR Microelectronics Co., Ltd.
Autodesk
Automotive Security Research Group (ASRG)
Avaya Inc.
Axis Communications AB
Baicells Technologies Co., Ltd.
Baidu, Inc.
Baxter Healthcare
Becton, Dickinson and Company (BD)
BeyondTrust Inc.
Bitdefender
BlackBerry
Brocade Communications Systems, Inc.
Canon EMEA
Canon Inc.
Carrier Global Corporation
Cato Networks
CERT.PL
CERT@VDE
Check Point Software Technologies Ltd.
Checkmarx
Checkmk GmbH
Ciena Corporation
cirosec GmbH
Cisco Systems, Inc.
ClickHouse, Inc.
Cloudflare, Inc.
Concrete CMS
CyberDanube
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government
Dassault Systèmes
Dell EMC
Dfinity Foundation
DirectCyber
Docker Inc.
dotCMS LLC
Dragos, Inc.
Dutch Institute for Vulnerability Disclosure (DIVD)
Eaton
Eclipse Foundation
ELAN Microelectronics Corp.
Elastic
EnterpriseDB Corporation
Environmental Systems Research Institute, Inc. (Esri)
Ericsson
ESET, spol. s r.o.
EU Agency for Cybersecurity (ENISA)
Exodus Intelligence
F5 Networks
Flexera Software LLC
Fluid Attacks
Forcepoint
Forescout Technologies
ForgeRock, Inc.
Fortinet, Inc.
Fortra, LLC
Gallagher Group Ltd
GE Healthcare
Genetec Inc.
Gitea Limited
GitHub (maintainer security advisories)
GitHub Inc, (Products Only)
GitLab Inc.
Glyph & Cog, LLC
Google LLC
Grafana Labs
Hanwha Vision Co., Ltd.
HashiCorp Inc.
HeroDevs
HiddenLayer, Inc.
Hillstone Networks Inc.
Hitachi Energy
Hitachi Vantara
Hitachi, Ltd.
Honeywell International Inc.
HP Inc.
Huawei Technologies
HYPR Corp
ICS-CERT
IDEMIA
Indian Computer Emergency Response Team (CERT-In)
Intel Corporation
Israel National Cyber Directorate
Ivanti
Jamf
JetBrains s.r.o.
Johnson Controls
JPCERT/CC
Kaspersky
KNIME AG
KrCERT/CC
Kubernetes
Lenovo Group Ltd.
Lexmark International Inc.
LG Electronics
Liferay, Inc.
Logitech
M-Files Corporation
ManageEngine
Mattermost, Inc
Mautic
Microchip Technology
Microsoft Corporation
Milestone Systems A/S
Mitsubishi Electric Corporation
MongoDB
Moxa Inc.
N-able
National Cyber Security Centre - Netherlands (NCSC-NL)
National Cyber Security Centre SK-CERT
National Instruments
Netflix, Inc.
Netskope
Network Optix
NLnet Labs
NortonLifeLock Inc
Nozomi Networks Inc.
Nvidia Corporation
Octopus Deploy
Okta
ONEKEY GmbH
Open Design Alliance
Open-Xchange
OpenAnolis
openEuler
OpenHarmony
OpenText (formerly Micro Focus)
OTRS AG
Palantir Technologies
Palo Alto Networks
Panasonic Holdings Corporation
Pandora FMS
PaperCut Software Pty Ltd
Patchstack OÜ
Payara
Pegasystems
Pentraze Cybersecurity
Perforce
Ping Identity Corporation
PostgreSQL
Progress Software Corporation
Proofpoint Inc.
Protect AI
Pure Storage, Inc.
QNAP Systems, Inc.
Qualcomm, Inc.
Qualys, Inc.
rami.io GmbH
Rapid7, Inc.
Robert Bosch GmbH
Rockwell Automation
SailPoint Technologies
Samsung TV & Appliance
SBA Research gGmbH
Schneider Electric SE
Schweitzer Engineering Laboratories, Inc.
Secomea
Securin
Security Risk Advisors
ServiceNow
SHENZHEN CoolKit Technology CO., LTD.
SICK AG
Siemens
Sierra Wireless Inc.
Silicon Labs
Snow Software
Snyk
SoftIron
SolarWinds
Sonatype Inc.
Sophos
Spanish National Cybersecurity Institute, S.A.
Splunk
STAR Labs SG Pte. Ltd.
Switzerland National Cyber Security Centre (NCSC)
Synaptics
Synology Inc.
Talos
TeamViewer Germany GmbH
Temporal Technologies Inc.
Tenable Network Security, Inc.
Thales Group
The Document Foundation
The Missing Link Australia (TML)
The Tcpdump Group
The Wikimedia Foundation
TianoCore.org
Tigera
Toshiba Corporation
TR-CERT (Computer Emergency Response Team of the Republic of Turkey)