Skip to content

CVE Object Reference

The CVE object is the canonical data structure returned by all CVE detail endpoints.

Top-Level Fields

Field Type Description
cve_id string CVE identifier (CVE-YYYY-NNNNN)
bsid string BreachSpider unique ID (BS-YYYY-NNNNNN-S)
title string Vulnerability title
description string Full vulnerability description
scoring object All scoring data (CVSS, EPSS, BCS)
exploitation object Active exploitation signals
affected object Affected vendors, products, protocols
patch object Patch availability and details
classification object CWEs, attack vector, layer
capec array CAPEC attack patterns inherited through the CVE's CWEs
sage object AI analysis
temporal object All timestamps
references object External URLs
_links object HATEOAS navigation links

scoring Object

scoring.cvss

Field Type Example
score float 10.0
vector string CVSS:3.1/AV:N/AC:L/...
version string 3.1
severity string CRITICAL
attack_vector string NETWORK
attack_complexity string LOW
privileges_required string NONE
user_interaction string NONE
scope string CHANGED
confidentiality_impact string HIGH
integrity_impact string HIGH
availability_impact string HIGH

scoring.epss

Field Type Description
score float 0.0-1.0 probability of exploitation
percentile float 0.0-1.0 relative to all CVEs
interpretation string Human-readable percentile label

scoring.bcs

BCS (BreachSpider Confidence Score) is BreachSpider's proprietary exploitation priority score combining CVSS, EPSS, KEV status, PoC availability, and ICS relevance.

Field Type Description
score float 0.0-10.0
tier string CRITICAL, HIGH, MEDIUM, LOW
factors.kev_flagged boolean In KEV catalog
factors.poc_available boolean Public PoC exists
factors.has_public_exploit boolean Functional exploit public
factors.patch_available boolean Vendor patch released
factors.ics_relevance float 0.0-1.0 ICS/OT relevance score

exploitation Object

Field Type Description
kev_flagged boolean KEV-confirmed active exploitation
kev_added_at string ISO 8601 date added to KEV
has_public_exploit boolean Functional exploit publicly available
poc_available boolean Proof-of-concept code available
exploit_maturity string NONE, POC, FUNCTIONAL, WEAPONIZED
actively_exploited boolean True when kev_flagged is true

Exploit Maturity Tiers

Maturity Meaning
NONE No exploit or PoC available
POC Proof-of-concept code published
FUNCTIONAL Working exploit available
WEAPONIZED On the CISA KEV catalog with no public exploit or PoC recorded. A KEV CVE with a public exploit reads FUNCTIONAL; check kev_flagged for known exploitation

affected Object

Field Type Description
vendors array List of affected vendor names
products array Reserved: currently always empty
primary_vendor string Reserved: currently always null
primary_product string Reserved: currently always null
vendor_count integer Total number of affected vendors
device_types array ICS device type classifications
protocols array Affected ICS protocols
ics_relevance_score float 0.0-1.0 ICS/OT relevance
ics_relevant boolean True when ics_relevance_score >= 0.5 or the CVE is linked to an industrial protocol

patch Object

Field Type Description
status string patched, unpatched, partial, workaround, unknown
patch_available boolean True when status is patched
patch_version string Fixed version (if known)
patch_url string Link to patch download (if known)
patch_notes string Remediation notes

sage Object

Field Type Description
model string AI model version
tier string full or blurred
executive_summary string AI-generated summary (all tiers)
ics_context string ICS/OT specific context (full tier)
remediation_guidance string Remediation steps (full tier)
confidence_score float AI confidence 0.0-1.0 (full tier)
confidence_tier string SOVEREIGN_AUDIT_PASS or lower
_upgrade_required boolean True when tier is blurred
_upgrade_url string Upgrade URL when blurred

temporal Object

Field Type Description
published_at string NVD publication date (ISO 8601)
modified_at string Last NVD modification date
enriched_at string BreachSpider enrichment timestamp
kev_added_at string Date added to KEV catalog

capec Object

CAPEC attack-pattern enrichment (Tier 1). Every CVE that carries a CWE weakness also carries the CAPEC attack patterns MITRE relates to that CWE. This gives attack-pattern context per CVE without any per-CVE labeling. It is built entirely from the CWE data already held plus the published MITRE CAPEC catalog.

capec is an array deduplicated by capec_id. It is always present: an empty array (never null) when the CVE has no related CAPEC.

Field Type Description
capec_id integer CAPEC attack-pattern identifier
name string CAPEC attack-pattern name
slug string URL slug, capec-{capec_id}
typical_severity string MITRE typical severity for the pattern
via_cwe array Bridging CWE ids that cite this mapping

via_cwe is the citation anchor. It names the CWE (or CWEs) on the CVE that MITRE maps to the attack pattern. When one attack pattern is reachable through more than one bridging CWE, the CAPEC appears once with every bridging CWE listed.

Sources

CAPEC enrichment uses the MITRE CAPEC catalog (version 3.9, 615 attack patterns) and MITRE's own CWE-to-CAPEC relationships (1,154 pairs). Each attack pattern is stamped with its catalog version and a checksum, so the exact release behind any pattern is auditable. For each CVE, the CWE weaknesses it lists are followed to the attack patterns MITRE maps to them; each pattern appears once, with every bridging CWE in via_cwe. MITRE's CAPEC-to-ATT&CK technique mappings are held but not yet exposed through the API.

Provenance and Correctness

The CWE-to-CAPEC relationship is authoritative and published by MITRE. It is not inferred by BreachSpider. It can be presented as a real mapping, cited by the bridging CWE.

This is distinct from any future ATT&CK derivation. Deriving ATT&CK from a CVE would chain a second inference on top of the CWE-to-CAPEC mapping, so when that step is built it must be labeled as derived. Authoritative CWE-to-CAPEC data and derived ATT&CK data are not the same, and derived ATT&CK must never be presented as authoritative.

Coverage

228,000 plus distinct CVEs return a non-empty capec array, which is 63 percent of the CVE base.

The honest gap: CWE coverage is 79 percent and CAPEC-inherited coverage is 63 percent. The difference is CWEs that MITRE CAPEC does not map to any attack pattern, plus 29 CAPEC-referenced hardware-class CWEs (CWE-1000 and up) that are absent from the current cwes set. This is the shape of MITRE's published data, not a defect in the enrichment.

Refreshing the Catalog

To refresh, re-run the Tier 1 ingest against a newer capec_latest.xml. The ingest is idempotent, so a re-run updates the catalog version and adds any new patterns without duplicating existing rows.