Common Vulnerability Scoring System(CVSS)
Dinesh kumar ,CISSP CISM
CISSP | CISM |Cyber Security Architect | Certified in Cybersecurity (ISC2) |AZ-500|SC-100|AZ-700|SC-200|SC-300|AZ-305|AZ-104|SC-900
CVSS is an open framework maintained by the?Forum of Incident Response and Security Teams?(FIRST). The Common Vulnerability Scoring System (CVSS) is used to rate the severity and risk of computer system security.
CVSS uses a numerical score to represent the severity of a vulnerability, ranging from 0 to 10. The score is calculated based on a set of metrics that assess the exploitability and impact of the vulnerability.
CVSS is consists of the following metric groups:
Base Score: This represents the intrinsic qualities of a vulnerability. It includes metrics such as the attack vector, attack complexity, privileges required, user interaction, and the scope of the impact.
Temporal Score: This reflects the characteristics of a vulnerability over time. It includes metrics such as the exploitability, remediation level, and the report confidence.
Environmental Score: This considers the impact of a vulnerability in a specific environment. It includes metrics related to the confidentiality, integrity, and availability impacts on the affected system.
The combination of these three scores provides a comprehensive assessment of the overall severity of a vulnerability.
Below is reference for CVSS score calculator.
领英推荐
CVSS Versions:
CVSS V1
CVSS V2
CVSS 3.0
CVSS 3.1
CVSS 4.0 (Latest)
Latest version CVSS 4.0 officially released in November, 2023.
what’s new in CVSS V4?