Lead the INCIBE page with the record scored CRITICAL after withdrawal

The 9.00 CRITICAL on a withdrawn identifier is the sharpest illustration of what the gap costs, and it sat mid-page as a single paragraph. It now opens the page as a four-way comparison: the record is rejected on cve.org, the issuing CNA claimed 7.6, we hold the chain cannot occur, and the national CERT presents 9.00. The sequence is stated too, since the CNA assigned 7.6, the listing raised it, and the CNA then withdrew the record, leaving the highest of the four scores as the one nobody stands behind.
This commit is contained in:
Classic298
2026-08-17 22:47:22 +02:00
parent ef0531be72
commit ec2f18082b
@@ -8,7 +8,7 @@ title: "INCIBE-CERT"
| | |
| :--- | :--- |
| **Product** | INCIBE-CERT early-warning vulnerability listing (Spain's national CERT) |
| **Problem** | Withdrawn records keep their CVSS scores and severity ratings, and one carries no rejection notice at all |
| **Problem** | Withdrawn records keep their CVSS scores and severity ratings, one is presented at 9.00 CRITICAL, and one carries no rejection notice at all |
| **First contacted** | 2026-08-08 |
| **Channels tried** | `empresas@` |
| **Status** | Awaiting response |
@@ -19,6 +19,25 @@ This page is not a general complaint about INCIBE-CERT's data quality. It concer
---
## A withdrawn record, presented as CRITICAL by a national CERT
Start with the single entry that shows what the gap costs. Four parties have assessed [CVE-2024-7053](https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2024-7053), and this is where each of them landed:
| Source | Assessment |
| :--- | :--- |
| The CVE record on cve.org | **`REJECTED`** since 2026-08-13 |
| The issuing CNA, at assignment | 7.6 High |
| Open WebUI | The described chain cannot occur, for four independent reasons |
| **INCIBE-CERT, today** | **9.00 CRITICAL** |
The highest score of the four is the one published by the national CERT. It exceeds what the issuing CNA itself claimed, on an identifier that same CNA has since withdrawn, describing an attack chain that could never have run.
The order matters. The CNA assigned it at 7.6. INCIBE-CERT raised it to 9.00. The CNA then withdrew the record entirely. The rating that survives on the early-warning listing is the one nobody stands behind: not the CNA, which retracted it, and not us.
A 9.00 CRITICAL is not a filing detail. It is the number that decides whether a security team drops what it is doing, whether a procurement review blocks, and whether a scanner escalates a build. Organisations read a national CERT's early-warning listing as guidance on what to act on, which is precisely the weight this entry carries and precisely what makes it costly. Our full assessment is on the [disposition page](/security/vendor-dispositions/cve-2024-7053).
---
## The rejection reaches the description and stops there
INCIBE-CERT does ingest reject transitions into the description field. On a withdrawn record the description is replaced with the CNA's notice, and nothing else on the page changes. Every one of these still displays a CVSS vector, a base score and a severity label:
@@ -61,16 +80,6 @@ The other eight entries carry INCIBE-CERT's own **Last modified** dates of 2026-
---
## A disputed record scored above its own CNA
[CVE-2024-7053](https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2024-7053) was still live here while its [dispute](/security/vendor-dispositions/cve-2024-7053) was before the CVE Program, so its presence was expected at the time of writing. The issuing CNA withdrew it on 2026-08-12 and the record has carried the `REJECTED` state on cve.org since 2026-08-13.
Its score was not expected. INCIBE-CERT presents it at **9.00 CRITICAL**. The issuing CNA claimed 7.6 High. Our position, set out in full on its disposition page, is that the described chain fails for four independent reasons and cannot occur at all.
Organisations read early-warning listings from a national CERT as guidance about what to act on.
---
## Contact log
| Date | Channel | Outcome |