DependencyTrack / DependencyTrack/dependency-track

Adding new hardware component without having a CPE assigned

Open
#1,413 1 comment 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

The enhancement may already be reported! Please search for the enhancement before creating one.

### Current Behavior:
We need to enter the complete CPE id (cpe:2.3:h-------) to get the CVEs reported against a particular hardware component.
This is the case with components with affected configuration has only hardware in it (only cpe:2.3:h).
e.g. https://nvd.nist.gov/vuln/detail/CVE-2017-5754, CPE id: cpe:2.3:h:intel:atom_c:c2308:*:*:*:*:*:*:*

### Proposed Behavior:
Currently DT is unable to track future CVEs on hardware components which may reported if there is no CPE id assigned already. This is the case with hardware components which doesn't have any CVEs reported yet.

e.g. Adding a hardware component say 'stm32l5' or 'stm32U5' which doesn't have any CVEs reported yet. How to add this component into DT if we don't know the CPE.

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or entry points. Start by tracing how hardware components, complete CPE identifiers, and NVD CVEs are handled, then compare components with existing CPEs against examples such as stm32l5 or stm32U5. Done means future CVEs can be tracked for a hardware component without an assigned CPE.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.