Notification received by a technology developer and/or provider from a vulnerability reporter, which may include a description of what product or service is affected, how the potential vulnerability can be identified, demonstrated, or reproduced, and what type of functional impact the vulnerability allows.
Sources:
NIST SP 800-161r1-upd1
[11/1/2024 errata update]
from
ISO/IEC 29147:2018 - adapted