Sectigo: Lack of documentation for vulnerability NVD rating adjustment
Sectigo disclosed an incident related to vulnerability management documentation discovered during its annual WebTrust audit. The CA reported that for two vulnerabilities requested as samples during the audit, it became aware that no proper internal documentation existed for the decision-making process leading to an adjustment of each vulnerability’s NVD rating. The incident was identified after WebTrust audit evidence requests and reminders, and Sectigo stated that it declared the matter an incident when it did not have further evidence available. Sectigo also reported that, while the vulnerabilities had already been patched, it recast the vulnerabilities in its scanning software with proper comments around the reasoning for the recast. In its remediation, Sectigo increased headcount responsible for vulnerability scanning and instigated a weekly, multi-person standing call for vulnerability scanning review. Sectigo provided a report closure summary stating that the disclosed action items were completed and requested closure, and the bug was resolved as FIXED.
- Vulnerability #1 was first discovered.
- Vulnerability #2 was officially registered as mitigated.
- Sectigo identified the lack of evidence and declared the matter an incident after receiving draft WebTrust audit reports.
- Sectigo recast the vulnerabilities in its scanning software with comments explaining the NVD rating recast reasoning.
- Sectigo posted the report closure summary and requested closure after completing action items.
- Sectigo — Martijn Katerbarg opened a preliminary incident report stating that no proper internal documentation existed for the decision process behind adjusting the vulnerabilities’ NVD ratings, discovered via the annual WebTrust audit.
- Sectigo — Martijn Katerbarg posted a full incident report with a timeline, root cause (single person responsibility), and remediation details.
- Sectigo — Martijn Katerbarg indicated they would post a report closure summary unless questions were raised.
- Sectigo — Martijn Katerbarg posted the report closure summary, stating action items were completed and requesting closure.
- CCADB representative — CCADB incident reporting requested final comments and stated the incident would be closed approximately 2025-07-15 if no questions were posted.