Glossary · OT security engineering
Coordinated vulnerability disclosure (CVD)
Also known as: CVD, Responsible disclosure
German: Koordinierte Schwachstellenoffenlegung (CVD)
In product security, coordinated vulnerability disclosure (CVD) is the process in which a vulnerability reporter, the affected manufacturer and, where needed, coordinators such as CSIRTs work together so that a vulnerability is fixed or mitigated before details are published, and users are informed through an advisory.
- Security engineering
- OT security
- Standards
In one sentence
Coordinated vulnerability disclosure (CVD) lets reporters, manufacturers and CSIRTs fix a vulnerability before details are published in an advisory.
Example
A researcher reports a flaw in a PLC web interface to the vendor's security contact; the vendor confirms it, develops a fix, and publishes an advisory with a CVE ID on an agreed date.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
How it applies
- Product development: Suppliers publish a CVD policy with a contact point, accept reports, acknowledge them, agree timelines with reporters and credit them where wanted. ISO/IEC 29147 covers disclosure; ISO/IEC 30111 covers the internal handling process.
- Compliance: The Cyber Resilience Act (CRA) requires manufacturers to put in place and enforce a coordinated vulnerability disclosure policy and to provide a contact address for reporting. NIS 2 establishes CSIRTs as coordinators for CVD.
- Operation: OT fixes take time to reach plants; advisories should therefore also offer mitigations for users who cannot update immediately.
- Documentation: The CVD policy, the security contact and the location of advisories should appear in product documentation and on the manufacturer's website, so that reporters and customers can find them easily.
Coordinated vulnerability disclosure vs. full disclosure
Full disclosure publishes vulnerability details immediately, before a fix exists. CVD delays publication until users can protect themselves, within an agreed time frame.