Common Vulnerability Scoring System CVSS 2.0 unifies vulnerability scoring
I’m a bit late writing about the release of the new Common Vulnerability Scoring System CVSS 2.0 released earlier this month.
It is a valuable addition to the already established MITRE OVAL Open Vulnerability and Assessment Language and WASC Web Security Threat Classification.
The Common Vulnerability Scoring System (CVSS) provides an open framework for communicating the characteristics and impacts of IT vulnerabilities. CVSS consists of 3 groups: Base, Temporal and Environmental. Each group produces a numeric score ranging from 0 to 10, and a Vector, a compressed textual representation that reflects the values used to derive the score.
- The Base group represents the intrinsic qualities of a vulnerability.
- The Temporal group reflects the characteristics of a vulnerability that change over time.
- The Environmental group represents the characteristics of a vulnerability that are unique to any user’s environment.
CVSS enables IT managers, vulnerability bulletin providers, security vendors, application vendors and researchers to all benefit by adopting this common language of scoring IT vulnerabilities.
I’m glad to see that ArcSight, one of my favorite security vendors, is one of the CVSS Adopters
If you enjoyed this post, make sure you subscribe to my RSS feed!
Thank you for reading this post. You can now Leave A Comment (0) or Leave A Trackback.
Post Info
This entry was posted on Friday, June 29th, 2007 and is filed under Vulnerabilities, Framework.You can follow any responses to this entry through the Comments Feed. You can Leave A Comment, or A Trackback.
Previous Post: Regression and Stress Tests with FunkLoad »
Next Post: New Windows WiFi Driver Enumerator : WiFiDEnum »
Read More
Related Reading:- Privacy Dilemma: How to Protect Yourself Online
- Solera Networks Deep-Packet Capture Review
- WordPress Exploit Scanner
- Phishing Exposed, Brands Secured
- Scanners: New Nessus Release; New eEye Web Scanner
- Good News from ArcSight and Imperva
- CCTV Security Camera and Surveillance Equipment
- OpenDNS Offers Free Web Content Filtering
- Can I Evade ScanSafe Anywhere+ ?
- Googlehacks and Anti-Googlehacks

