Daylight saving has resulted in the NIST parsing being too strict: $ ./bin/srtool_nist.py -n --source="NIST 2018" --file=data/nvdcve-1.0-2018.json --url-file=nvdcve-1.0-2018.json.gz --url-meta=nvdcve-1.0-2018.meta BEGINNING NIST UPDATES PLEASE WAIT ... this can take some time DATABASE UPDATED FAILED ... time data 'lastModifiedDate:2018-11-08T03:06:21-05:00\r\n' does not match format 'lastModifiedDate:%Y-%m-%dT%H:%M:%S-04:00\r\n'
Remove UTC offset to avoid timezone/day light savings errors.
$ ./bin/srtool_nist.py -n --source="NIST 2018" --file=data/nvdcve-1.0-2018.json --url-file=nvdcve-1.0-2018.json.gz --url-meta=nvdcve-1.0-2018.meta BEGINNING NIST UPDATES PLEASE WAIT ... this can take some time [ 99] CVE-2018-9999 DATABASE UPDATE FINISHED
Just discovered this in the NIST description field for new CVEs: ERROR(1):b'Traceback (most recent call last): File "bin/srtool_nist.py", line 695, in <module> main(sys.argv[1:]) File "bin/srtool_nist.py", line 643, in main fetch_cve(args.cve_detail,args.cve_file) File "bin/srtool_nist.py", line 594, in fetch_cve summary[\'cpe_list\'] += nist_scan_configuration_or(config, cve_name, 0)\n File "bin/srtool_nist.py", line 606, in nist_scan_configuration_or for cpe in cpe_or_node[\'cpe\']:\nKeyError: \'cpe\''
NIST is its wisdom has added or replaced the "cpe" sub-table with "cpe-match" in the 2018 tables. The 2015 sub-table still uses "cpe". The updated code now accepts both table names when scanning CPE entries.
Confirmed fixed.