3 ms·
It's best to avoid reading much meaning into CVE scores. So much depends on the perennial question "what's your threat model?"
by mkj 3y ago
It's best to avoid reading much meaning into CVE scores. So much depends on the perennial question "what's your threat model?"
- Fnoord 3y agoThis question and many more can be applied on using CVSSv3. So a pentester doesn't have to use CVE scores as holy bible in their report. A risk assessment can be worked upon by those who are going to consider the recommendations in the report.