Skip to content

so what is VEX anyway? #127

Closed Answered by zmanion
zmanion asked this question in General
Mar 10, 2023 · 11 comments · 29 replies
Discussion options

You must be logged in to vote

Art, When you say CISA will be publishing the VEX document, does this mean the VEX document will be subject to the same approval process required by other CISA publications, such as the ICT_SCRM Task Force guidebooks?

I don't know the approvals processes, but Minimum Requirements for Vulnerability Exploitability eXchange (VEX) was published a couple weeks ago.

Quoting from that document, I propose that the answer to this discussion is:

Vulnerability Exploitability eXchange (VEX) indicates the status of a software product or
component with respect to a vulnerability. A common VEX use case is to indicate that software
is or is not affected by a vulnerability.

...machine-readable collec…

Replies: 11 comments 29 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@henkbirkholz
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
7 replies
@tracymiranda
Comment options

@rjb4standards
Comment options

@henkbirkholz
Comment options

@JasonKeirstead
Comment options

@rjb4standards
Comment options

Comment options

You must be logged in to vote
2 replies
@zmanion
Comment options

zmanion Mar 14, 2023
Collaborator Author

@oliverchang
Comment options

Comment options

You must be logged in to vote
9 replies
@JasonKeirstead
Comment options

@rjb4standards
Comment options

@msmeissn
Comment options

@rjb4standards
Comment options

@JasonKeirstead
Comment options

Comment options

You must be logged in to vote
2 replies
@JasonKeirstead
Comment options

@JasonKeirstead
Comment options

Comment options

You must be logged in to vote
1 reply
@JasonKeirstead
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

zmanion
Apr 12, 2023
Collaborator Author

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
7 replies
@zmanion
Comment options

zmanion May 9, 2023
Collaborator Author

Answer selected by zmanion
@rjb4standards
Comment options

@stevespringett
Comment options

@rjb4standards
Comment options

@zmanion
Comment options

zmanion May 9, 2023
Collaborator Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
10 participants