3 ms·
> Ah, yes, this is the "start from the assumption that everything has failed" trick. I am actually fairly data driven, and it's why things like SBOMs are excit
by genmud 3y ago
> Ah, yes, this is the "start from the assumption that everything has failed" trick.
I am actually fairly data driven, and it's why things like SBOMs are exciting. Based on my experience, if something is exposed to the world and that thing has a vulnerability... within a period of reasonable time (say within 12 months), it will be exploited.
> No, sorry, I do not care that (e.g.) CVE-2023-4911 has been categorized as "high"
I wasn't actually referring to my "high" being the cvss scores. It was likelihood of exploitation(in my org), not the score. In your example, that would be a local exploit, so wouldn't be a high in my book unless you are shoveling user input to a CLI, which I would hope isn't happening.
Personally unless you know there to be higher risks for certain things, if it ain't 9+ on cvss, it gets a ticket cut to deal with it like any other but at some convenient time in the future.
> but what we actually get is "raw CVSS score tells you all you need to know and absolutely dictates urgency and triage priority"
Your security org sucks and are doing it wrong. I'm genuinely sorry, and I'll say that not all of us are like that :(