You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Python脚本无法追加解析NVD XML数据至CSV且无报错求助

Hey there! Let's figure out why your NVD XML parsing isn't pulling in those remote-execution vulnerabilities and updating your CSV. It’s totally possible that your findall() calls aren’t targeting the right elements—NVD’s XML structure has a few tricky quirks that trip up a lot of folks. Here are the most likely issues and fixes:

Common Culprits & Fixes

1. You’re Ignoring XML Namespaces (The #1 Gotcha)

NVD’s XML uses a default namespace (usually something like xmlns="http://scap.nist.gov/schema/vulnerability/0.4"). If you don’t account for this in your XPath queries, findall() will return an empty list every time, even if the elements exist.

Fix: Define the namespace mapping and include it in your findall() calls:

# Match the xmlns value from your XML's root element
ns = {'nvdcve': 'http://scap.nist.gov/schema/vulnerability/0.4'}
# Now use the namespace prefix in your XPath
access_vectors = root.findall('.//nvdcve:access_vector', namespaces=ns)

2. Your XPath Path Is Wrong (Check XML Structure)

NVD’s XML hierarchy changes between CVSS versions (2.0 vs 3.0), so your XPath might be pointing to the wrong place:

  • For CVSS 2.0: The access vector lives at cvss/access_vector
  • For CVSS 3.0: It’s renamed to attackVector under cvssV3, and the value is uppercase (NETWORK instead of Network)

Debug Tip: Print all element tags in your XML to see the actual structure:

for elem in root.iter():
    print(elem.tag)  # Will show the full namespace-qualified tag, e.g., {http://scap.nist.gov/schema/vulnerability/0.4}access_vector

3. Your XML Input Is Empty or Malformed

Double-check that you’re loading the correct XML file/API response. Try printing the root element to confirm data is being parsed:

print(root)  # Should show the root tag with the namespace

If this looks off, verify your XML source (e.g., check if the API request returned valid data, or if your local file isn’t corrupted).

4. CSV Appending Logic Might Be Silent

Even if you find data, your CSV code might not be writing it correctly. Make sure:

  • You’re opening the file in append mode ('a') with newline='' to avoid extra blank rows
  • You’re only writing when you actually find matching vulnerabilities (add a print statement inside your match condition to confirm hits)
Example Working Snippet

Here’s a simplified version that handles namespaces and checks for CVSS 2.0/3.0 remote vulnerabilities:

import xml.etree.ElementTree as ET
import csv

# Define namespace (update to match your XML's xmlns)
ns = {'nvdcve': 'http://scap.nist.gov/schema/vulnerability/0.4'}

# Parse XML (replace with your file path or API response content)
tree = ET.parse('nvd_feed.xml')
root = tree.getroot()

# Append to CSV
with open('remote_vulns.csv', 'a', newline='', encoding='utf-8') as csvfile:
    writer = csv.DictWriter(csvfile, fieldnames=['CVE_ID', 'Access_Vector', 'Description'])
    
    # Write header if file is empty
    csvfile.seek(0, 2)
    if csvfile.tell() == 0:
        writer.writeheader()

    for cve in root.findall('.//nvdcve:cve', namespaces=ns):
        cve_id = cve.find('.//nvdcve:id', namespaces=ns).text
        
        # Check CVSS 2.0
        av_2 = cve.find('.//nvdcve:access_vector', namespaces=ns)
        if av_2 and av_2.text.strip() == 'NETWORK':
            desc = cve.find('.//nvdcve:description', namespaces=ns).text.strip()
            writer.writerow({
                'CVE_ID': cve_id,
                'Access_Vector': av_2.text,
                'Description': desc
            })
            print(f"Added {cve_id} (CVSS 2.0)")
        
        # Check CVSS 3.0
        av_3 = cve.find('.//nvdcve:attackVector', namespaces=ns)
        if av_3 and av_3.text.strip() == 'NETWORK':
            desc = cve.find('.//nvdcve:description', namespaces=ns).text.strip()
            writer.writerow({
                'CVE_ID': cve_id,
                'Access_Vector': av_3.text,
                'Description': desc
            })
            print(f"Added {cve_id} (CVSS 3.0)")

Start by adding print statements to see if findall() is returning any elements. If it’s still empty, share a snippet of your XML structure and we can tweak the XPath further!

内容的提问来源于stack exchange,提问作者lanceDamage

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:50:56