Hello,I am comparing the affected version lists published by Cisco in two formats forthe same advisory, and I consistently find a difference. I would like tounderstand whether this is expected.== Example 1: cisco-sa-asa-ftd-ios-dos-kPEpQGGK / CVE-2026-20012 ==CSAF (product_status.known_affected, relationships expanded) : 1,429 versionsCVE Record (containers.cna.affected[].versions) : 1,271 versionsVersions present in CSAF but not in the CVE Record : 158The CVE Record is a strict subset of the CSAF. The difference is not caused bynotation (normalising parentheses, dots and leading zeros resolves none of them),and both documents were published on 2026-03-25, three minutes apart.The difference is limited to two product lines:IOS 647 in CSAF, 94 missing (14.5%)Cisco IOS XE Software 442 in CSAF, 64 missing (14.5%)Secure Firewall ASA 235 in CSAF, 0 missing (0%)Secure Firewall FTD 105 in CSAF, 0 missing (0%)I checked whether the missing versions are simply unknown to Cisco. They are not.Querying the openVuln APIGET /security/advisories/v2/OSType/{ios|iosxe}?version={version}returns HTTP 200 for 131 of the 132 missing versions I tested, and every one ofthose responses includes this advisory. Two thirds of them also return afirstFixed value, so a fixed release exists.Entire trains are absent from the CVE Record while being fully present in CSAF,for example 15.4(3)M (all 13 versions) and IOS XE 3.10.xS (all 16 versions).== Example 2: cisco-sa-ios-xmcp-thbAr34t / CVE-2026-20301 ==CSAF (snapshot taken the day after publication) : 541 versionsCVE Record : 427 versionsMissing : 114Here the excluded set is different. Trains such as 15.3(3)M, 15.5(3)M, 15.6(3)M,15.5(3)S and 15.4(3)S are completely absent from this CVE Record, although thesame trains are present in the CVE Record for CVE-2026-20012 published fivemonths earlier.== Questions ==1. Is this difference expected and documented somewhere?2. For the operating systems supported by Cisco Software Checker, which sourceshould be treated as authoritative for affected versions - the CSAF, or theCVE Record?3. Consumers that rely on the CVE Record or on NVD will not match a devicerunning, for example, 15.4(3)M5, even though Software Checker reports it asaffected. Is there any plan to align the two outputs?Thank you.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Re: How to step update version asa firepower 1140 | 0 | 11.77 | 05-10-2026 |
| 2 | Какие наши продукты задевает эта CVE? Я продолжил заброшенный Minefield и нашёл, что он читал SBOM задом наперёд | 0 | 9 | 26-09-2026 |
| 3 | WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV | 0 | 9.71 | 25-09-2026 |
| 4 | Re: ISE 3.3 Patc 5- user cannot change password if expire | 0 | 5.96 | 05-10-2026 |
| 5 | Re: ISE 3.3 Patc 5- user cannot change password if expire | 0 | 19.01 | 05-10-2026 |
| 6 | Re: How to step update version asa firepower 1140 | 0 | 8.82 | 05-10-2026 |
| 7 | Navigating Cyber Disclosures in 2026: A Limited Renewal of CISA 2015, and “Take Two” on Finalizing CIRCIA’s Reporting Regulations | 0 | 11.74 | 26-02-2026 |
| 8 | Re: ISE 3.3 Patc 5- user cannot change password if expire | 0 | 22.24 | 05-10-2026 |
| 9 | CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally | 0 | 7.63 | 28-09-2026 |
| 10 | Re: EoMPLS VC Type 4 and VC Type 5 | 0 | 8.89 | 05-10-2026 |