Data provider-independent vulnerability management in Versio.io
Review of the termination of MITRE funding by the US government
Free trial In a nutshell NIS2 🇩🇪Short version
- The recent actions of the US government under Donald Trump, in particular the cut in funding for the MITRE Corporation, jeopardize the long-term stability of one of the world's leading databases for IT security vulnerabilities. As a result of the worldwide protest, the US government has now pledged funding for a further year.
- Versio.io relies on a generic, internally developed model for managing vulnerabilities (Common Vulnerabilities and Exposures, CVEs) and at the same time offers the flexible integration of a wide variety of data sources - including public vulnerability databases and vendor-specific security advisories. Thanks to this approach, Versio.io is independent of individual institutions, centralized data sources and possible political influences.
- The discontinuation of the publication of new vulnerabilities by MITRE would be a loss of information for customers and manufacturers of software solutions in the IT security sector, which is very likely to be absorbed promptly by new organizational units (e.g. European Vulnerability Database of the European Union).
- The US government's decision has once again raised global awareness of the importance of vulnerability databases. Versio.io assumes that the trend towards decentralized, distributed data storage will continue - combined with higher availability and improved content quality of the vulnerability information provided.
What has the US government decided?
What is the general impact of the US government's decision?
What does this mean for Versio.io customers?
Data source | Number of vulnerabilities |
---|---|
National Vulnerability Database (MITRE/NIST) | 289.742 |
GitHub Advisory Database | 273.868 |
Red Hat Security Advisory | 38.716 |
Juniper Security Advisory (JSA) | 1.132 |
Palo Alto Networks Security Advisories | 434 |
- European Vulnerability Database (EUVD) of the European Union: https://euvd.enisa.europa.eu
- Open Source Vulnerabilities (OSV): https://osv.dev
- VDE Cert for OT/IoT: https://www.vde.com/topics-de/digital-security/cert-vde
References
Author

Keywords