VEX

Vulnerability Exploitability eXchange

VEX is a machine-readable format with which a manufacturer communicates whether a product is actually affected by and exploitable through a particular vulnerability — or not. It is the most important complement to the SBOM because it reduces the flood of potential hits to the truly relevant ones. It answers the question „Does this even affect me?“.

History & facts. An SBOM shows that a vulnerable component is contained — but not whether the vulnerability is reachable or exploitable at all in the concrete product. VEX closes exactly this gap: the manufacturer states a status per vulnerability, typically „not affected“, „affected“, „fixed“ or „under investigation“, often with justification. The concept is driven by the US agency CISA in the environment of SBOM work; widespread implementations are CSAF VEX (based on the OASIS standard CSAF), CycloneDX VEX and OpenVEX. Outlook & recommendation. Without VEX, SBOM-based scanning quickly leads to alert fatigue because many reported vulnerabilities are not exploitable at all in the concrete deployment. VEX makes vulnerability management efficient by directing attention to the essentials — especially valuable when tight deadlines must be met under the CRA and NIS2. It is advisable to operate SBOM and VEX together and to feed both, automatically, into one's own vulnerability and threat data processing.
VEX — Vulnerability Exploitability eXchange