CNA vs Root vs ADP: CVE Program Roles Compared
Last reviewed
In the CVE Program, a CNA assigns CVE IDs and publishes records within its scope, a Root manages and trains a group of CNAs and allocates blocks of IDs to them, and an ADP (Authorized Data Publisher) enriches existing CVE records without assigning any IDs. MITRE and CISA are the two Top-Level Roots. CISA's Vulnrichment is the main ADP, adding SSVC, CVSS, CWE, and CPE data to published records.