We need (at least)
- A clear policy from the CNAs that describes exactly which bugs should be assigned CVEs.
- A process by which bogus CVEs can be invalidated, and CVE spammers can be banned from further submissions.
- A way to register CVEs for vulnerabilities that span multiple programs.
- e.g. an HTTP proxy has a low-risk bug, and an HTTP server has a low-risk bug, but when the proxy and the server are deployed together, the bugs become exploitable.
- An appeals process for CVE description updates. - e.g. You would not know from the description that CVE-2023-34188 is trivially exploitable and can reliably lock up vulnerable servers because MITRE refuses to update it.