-
34
pages
-
English
-
Documents
Description
Common Vulnerability Scoring System (CVSS) Version 2Karen Scarfone, NISTAcknowledgements FIRST conference presentation, Gavin Reid, Cisco Systems CVSS v2 Complete Documentation, FIRST CVSS-SIGDisclaimer: Certain commercial equipment or materials are identified in this presentation in order to adequately specify and describe the use of CVSS. Such identification is not intended to imply recommendation or endorsement by NIST, nor is it intended to imply that the materials or equipment identified are necessarily the best available for the purpose.Agenda Introduction and overview of CVSS Why CVSS? Base scores Temporal scores Environmental scores Example Score usageOverview Common Vulnerability Scoring System (CVSS) A universal way to convey vulnerability severity and help determine urgency and priority of responses A set of metrics and formulas Solves problem of multiple, incompatible scoring systems in use today Under the custodial care of FIRST CVSS-SIG Open, usable, and understandable by anyoneth, Version 2 released on June 20 2007Why CVSS? 20+ new vulnerabilities a day for organizations to prioritize and mitigate Vendors, coordinators, users need a common way to communicate Historically, vendors have used proprietary scoring systems. A 2006 CRN article showed that for CVE-2006-4128, a sampling of scores were 8.8/10 (Symantec), 4.2/10 (NVD), Moderately critical-3/5 (Secunia), High-3/3 (ISS), and Critical-4/4 ...
-
Publié par
-
Langue
English