A new European Union Vulnerability Database (EUVD) was introduced via a legislative act in 2022. The paper examines empirically the meta-data content of the new EUVD. According to the results, actively exploited vulnerabilities archived to the EUVD have been rather severe, having had also high exploitation prediction scores. In both respects they have also surpassed vulnerabilities coordinated by European public authorities. Regarding the European authorities, the Spanish public authority has been particularly active. With the exceptions of Finland, Poland, and Slovakia, other authorities have not engaged thus far. Also the involvement of the European Union's own cyber security agency has been limited. These points notwithstanding, European coordination and archiving to the EUVD exhibit a strong growth trend. With these results, the paper makes an empirical contribution to the ongoing work for better understanding European cyber security governance and practice.
翻译:欧盟漏洞数据库(EUVD)于2022年通过一项立法案正式设立。本文对该新数据库的元数据内容进行了实证分析。结果显示,归档至EUVD的已遭主动利用的漏洞普遍较为严重,且具有较高的利用预测评分。在这两方面,这些漏洞均超越了由欧洲公共机构协调处理的漏洞。就欧洲各机构而言,西班牙公共机构的表现尤为活跃。除芬兰、波兰和斯洛伐克外,其他机构迄今尚未参与其中。此外,欧盟自身网络安全机构的参与也较为有限。尽管如此,欧洲范围内的协调工作及向EUVD的归档呈现强劲增长态势。基于上述发现,本文为深入理解欧洲网络安全治理与实践的持续研究提供了实证依据。