Cve Metadata Schema#

        graph LR
    CVEMetadataFeed -- RESOURCE --> CVEMetadata
    

CVEMetadata#

Enrichment metadata for a CVE, sourced from NVD and EPSS.

Properties#

Field

Index

Description

id

Yes

CVE identifier.

firstseen

Timestamp when a sync job first created this node.

lastupdated

Yes

Timestamp of the last sync that observed this node.

attack_complexity

CVSS attack complexity metric.

attack_vector

CVSS attack vector metric.

availability_impact

CVSS availability impact metric.

base_score

CVSS base score.

base_severity

CVSS base severity rating.

cisa_action_due

CISA KEV remediation due date.

cisa_exploit_add

Date when CISA added the CVE to the KEV catalog.

cisa_required_action

Remediation action required by CISA.

cisa_vulnerability_name

CISA vulnerability name.

confidentiality_impact

CVSS confidentiality impact metric.

cvss_version

CVSS version selected from the NVD metrics.

description

English description of the vulnerability.

effect_tags

Controlled technical effects derived from mapped CWEs when available, otherwise from high CVSS confidentiality, integrity, and availability impacts plus the network straight-shot rule. Values are execute-code, gain-privileges, access-credentials, bypass-control, disclose-data, tamper-data, and deny-service.

effect_tags_source

Derivation source for effect_tags: cwe takes strict precedence over the cvss fallback, and none indicates that no usable effects were found.

epss_percentile

EPSS percentile ranking from 0.0 to 1.0.

epss_score

EPSS probability of exploitation from 0.0 to 1.0.

exploitability_score

CVSS exploitability score.

impact_score

CVSS impact score.

integrity_impact

CVSS integrity impact metric.

is_kev

Yes

Whether the CVE appears in the CISA KEV catalog.

last_modified_date

Date and time when the CVE was last modified.

privileges_required

CVSS privileges required metric.

problem_types

CWE identifiers associated with the vulnerability.

published_date

Date and time when the CVE was published.

references

Reference URLs for the vulnerability.

scope

CVSS scope metric.

user_interaction

CVSS user interaction metric.

vector_string

CVSS vector string.

vuln_status

NVD vulnerability analysis status.

Relationships#

  • (:CVEMetadata)-[:ENRICHES]->(:CVE): CVE metadata enriches its corresponding CVE.

  • (:CVEMetadataFeed)-[:RESOURCE]->(:CVEMetadata): A CVE metadata feed contains CVE metadata as a managed resource.

CVEMetadataFeed#

The enrichment feed used to manage CVE metadata lifecycle.

Properties#

Field

Index

Description

id

Yes

CVE metadata feed identifier.

firstseen

Timestamp when a sync job first created this node.

lastupdated

Yes

Timestamp of the last sync that observed this node.

source_epss

Whether EPSS enrichment was enabled for the sync.

source_nvd

Whether NVD enrichment was enabled for the sync.

Relationships#

  • (:CVEMetadataFeed)-[:RESOURCE]->(:CVEMetadata): A CVE metadata feed contains CVE metadata as a managed resource.