NetDEF — CVE Numbering Authority

The Network Device Education Foundation (NetDEF) is an authorized CVE Numbering Authority (CNA) in the CVE Program.

What is a CNA?

A CVE Numbering Authority (CNA) is an organization authorized by the CVE Program to assign CVE IDs to vulnerabilities and to publish CVE Records within a specific scope. CNAs are the front line of the CVE Program: they coordinate with researchers and maintainers, reserve CVE IDs, and publish the authoritative record describing each vulnerability — what is affected, how severe it is, and where to find fixes. See the CVE Program partner information for details on how the program is organized.

NetDEF as the CNA for FRRouting

NetDEF operates as the CNA for the FRRouting project. We assign and publish CVEs for security vulnerabilities in FRRouting.

If you have found a security issue in FRRouting, please report it to security@lists.frrouting.org. Before reporting or disclosing, please read our CNA Disclosure Policy.

You can browse all published FRRouting CVEs in the FRRouting CVE database.

Reporting infrastructure issues

For security issues in NetDEF / FRRouting infrastructure (CI, mailing lists, package archives, or any netdef.org / frrouting.org website), contact security@netdef.org.