---
title: The Dirty Dozen Vendors Deluging Your Vulnerability Management Team
description: The Dirty Dozen Vendors Deluging Your Vulnerability Management Team
image: https://businessinsights.bitdefender.com/hubfs/vulnerability.png
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

[#Privacy and Data Protection](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)

 By [**Ericka Chickowski**](https://businessinsights.bitdefender.com/author/ericka-chickowski) / Feb 26, 2018

# The Dirty Dozen Vendors Deluging Your Vulnerability Management Team

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/vulnerability-management-team&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/vulnerability-management-team&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/vulnerability-management-team&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/vulnerability-management-team&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/vulnerability-management-team&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/vulnerability-management-team&utm_medium=social&utm_source=facebook)

We've all heard about the 80/20 rule in business. But in vulnerability management, it may be more like the 54/12 rule. According to a [new report out last week](https://pages.riskbasedsecurity.com/2017-ye-vulnerability-quickview-report) by vulnerability intelligence firm Risk Based Security, in 2017 about 54% of all new vulnerabilities came from just 12 vendors.

It's a heady list of the who's who in enterprise systems, with plenty of obvious contenders and a few surprises, too. The top 12 based on volume of catalogued vulns is as follows:

1. Oracle
2. SUSE
3. Google
4. Red Hat
5. Canonical
6. IBM
7. Microsoft
8. Samsung
9. Apple
10. Cisco
11. Adobe
12. HPE

Among this collection of vendors, the typical severity of vulnerabilities was medium, with an average CVSSv2 score of 6.54. There were a couple of outliers when it comes to average severity--namely from Adobe and HPE. While these firms had the fewest enumerated vulnerabilities, they had a much stronger concentration of high severity flaws. Adobe's average CVSSv2 score was 8.01 and HPE's was 7.13. This is just a speculation, but given this inverse relationship between volume and severity rating, this could be a reflection on the disclosure and patch release policies of these two organizations rather than an indication of their true vulnerability posture.

![vulnerabilties-major-vendors.png](https://businessinsights.bitdefender.com/hubfs/vulnerabilties-major-vendors.png)

Source: Risk Based Security, Year-End 2017 Vulnerability QuickView Report

When it comes to vendors with the highest volume of very severe vulnerabilities--with scores of 9.0 to 10.0--the mix changes. Top five vendors here were Google, SUSE, Canonical, Red Hat and SGP (a subsidiary of Silent Circle).

Overall, the fact that just a few vendors dominate the found vulnerability database for 2017 is probably a good sign for the industry. It's likely an indication that these larger vendors are getting better at finding vulnerabilities in their software and responding to external discoveries by independent security researchers. According to this report, coordinated vulnerability disclosure has been on the uptick since 2013. Since then the number of coordinated vulnerabilities has increased by 16.7 percentage points based on the vulnerabilities aggregated, according to Risk Based Security.

"One factor in this increase is the rising popularity of GitHub, where users can submit issues to the software vendor/developer directly," the report explains. "While the information is made public right away, many developers do not specify any other method to report an issue, even if it has a security impact. So researchers following the developer's guidelines and reporting issues via the bug trackers is coordinated."

Last year, about 45% of vulnerabilities came as the result of coordinated disclosure, and another 19% from uncoordinated disclosure--figures that show how important vendor outreach to the security community is in addressing the kinds of flaws that impact their customers.

Overall, Risk Based Security published 20,832 vulnerabilities last year, a sizeable 31% increase over 2016. Among this total pool of security flaws, 39% had a CVSSv2 score of above 7.0 and 49% could be exploited remotely. Among the total list of flaws, just under a quarter of them have no known solution. 

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/yahoo-data-breaches-value-acquisition-verizon?hsLang=en-us>

### [Epic Yahoo Data Breaches Lead to Big Drop in Value Prior to Planned Acquisition By Verizon](https://businessinsights.bitdefender.com/yahoo-data-breaches-value-acquisition-verizon?hsLang=en-us)

<https://businessinsights.bitdefender.com/verizon-data-breach-report-organizations-need-to-do-more-security-work?hsLang=en-us>

### [Verizon Data Breach Report: Organizations Need to Do More Security Work](https://businessinsights.bitdefender.com/verizon-data-breach-report-organizations-need-to-do-more-security-work?hsLang=en-us)

<https://businessinsights.bitdefender.com/average-ddos-attack-volume-in-europe-tripled-in-a-year-new-data-reveals?hsLang=en-us>

### [Average DDoS Attack Volume Tripled in a Year, New Data Reveals](https://businessinsights.bitdefender.com/average-ddos-attack-volume-in-europe-tripled-in-a-year-new-data-reveals?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Ericka Chickowski",
    "url" : "https://businessinsights.bitdefender.com/author/ericka-chickowski"
  },
  "datePublished" : "2018-02-26T08:05:54.000Z",
  "headline" : "The Dirty Dozen Vendors Deluging Your Vulnerability Management Team",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/vulnerability.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/vulnerability-management-team",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```