Cybersecurity definition
What is VEX?
VEX stands for Vulnerability Exploitability eXchange.
By Cyber Tool Stack Editorial TeamUpdated
Definition
A companion standard to SBOM that states whether a known vulnerability in a listed component is actually exploitable in the way the software uses it, cutting down the noise of vulnerabilities that technically exist but can't be triggered.
Where VEX fits in the security landscape
These beginner lessons use this term while explaining the surrounding security control.
Related cybersecurity terms
SBOMSoftware Bill of MaterialsA formal, machine-readable inventory of every open-source and third-party component that makes up a piece of software, so an organization can quickly tell whether a newly disclosed vulnerability affects anything it runs.CVECommon Vulnerabilities and ExposuresA public catalog that assigns a unique identifier to a specific, publicly known software or hardware vulnerability, so vendors, researchers, and tools can all refer to the same flaw unambiguously.