← Sectigo cases
Bugzilla #1972158
Certificate Problem Report
Sectigo: Lack of documentation for vulnerability NVD rating adjustment
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo reported an incident regarding the lack of documentation for the adjustment of NVD ratings for two vulnerabilities discovered during their annual WebTrust audit. The issue stemmed from a single person being responsible for vulnerability management, leading to inadequate documentation of the decision-making process. Following the incident, Sectigo has increased personnel responsible for vulnerability management and established a weekly review call to ensure proper oversight. The case has been resolved with all action items completed.
Chronology
- Vulnerability #1 is first discovered.
- Non-compliance identified date.
- Report Closure Summary posted.
Participants
Martijn Katerbarg
External References
Similar Local Cases
Sectigo: Non-existent hostname in CDP and AIA URLs
Sectigo: HTML encoded characters in subject attribute values
Sectigo: Intermittent OCSP unauthorized responses for certificates older than 15 minutes
Sectigo: OV reuse data applied for wrong organization
Sectigo: Package patching gap within Certificate Systems
Sectigo: Premature disabling of CRL generation for an inactive CA
Sectigo: Late receipt and disclosure to CCADB of ETSI audit letters
Sectigo: OCSP, caIssuers, and CRL endpoints unavailable for a single Subordinate CA