3 ms·
Assigning severity to vulnerabilities is a very difficult problem. This is exacerbated by the fact that most modern exploits are chains of multiple vulnerabili
by grajaganDev 2y ago
Assigning severity to vulnerabilities is a very difficult problem.
This is exacerbated by the fact that most modern exploits are chains of multiple vulnerabilities.
I think a vulnerability should be scored based on the context where the most damage could be done.
- CharlesW 2y ago> I think a vulnerability should be scored based on the context where the most damage could be done. As I read it, the point of the article is that CVSS makes sense in the case where you know that, but is near-useless when you don't.
- duskwuff 2y agoAnd in practice, it means CVSS is only really meaningful on software which exists as a complete system, like a web application or a device - questions like "is user interaction required to exploit this vulnerability" are usually unanswerable for individual software components.