CVD

Coordinated Vulnerability Disclosure

Koordinierte Offenlegung von Schwachstellen

CVD denotes the coordinated approach in which the finder of a vulnerability and the affected vendor jointly manage publication: fix first, then disclose. The aim is to protect users without giving attackers an unnecessary head start. CVD is the broadly accepted middle path today between immediate secrecy and immediate full disclosure.

History & facts. Handling discovered vulnerabilities was long a point of contention between researchers and vendors. CVD prevailed as a consensus and is detailed in international standards — ISO/IEC 29147 describes disclosure, ISO/IEC 30111 the vendor-side handling. A common practice is an agreed deadline after which publication occurs even without a patch — as leverage against inaction. Outlook & recommendation. With the CRA, a functioning disclosure and handling process becomes effectively mandatory for manufacturers. Those developing products should establish a clearly reachable reporting channel and a defined internal workflow (ideally via a PSIRT) before the first report arrives. For finders: the coordinated route protects not only users but also offers better legal footing than going it alone.
CVD — Coordinated Vulnerability Disclosure