NIST to stop rating non-priority flaws due to volume increase
Because of the increasing volume of submissions, the National Institute of Standards and Technology will no longer assign severity levels to lower-priority vulnerabilities.
Beginning on April 15, the service will only examine and offer supplementary information (such as product listings and severity ratings) for security vulnerabilities that satisfy particular standards pertaining to the risk they represent.
All submitted vulnerabilities will still be listed in the National Vulnerability Database (NVD), however those deemed low priority will only receive a severity rating from the CVE Numbering Authority (CNA) that assessed and filed them.
The non-regulatory federal agency stated in a statement this week that it will only offer more information on vulnerabilities that satisfy one...


