The Common Vulnerability Scoring System (CVSS) is a standard for assessing the criticality of security vulnerabilities in computer systems and networks. CVSS was commissioned in 2005 by the National Infrastructure Advisory Council (NIAC), a working group of the US Department of Homeland Security. It is currently maintained by the Forum of Incident Response and Security Teams.

The CVSS evaluates security vulnerabilities according to various criteria in order to enable a uniform assessment of these in different systems, to facilitate the prioritization of measures to remedy these vulnerabilities and to make them comparable with each other overall. CVSS evaluates vulnerabilities quantitatively on a scale from 0 to 10, with 10 being the highest criticality. In detail 8 different categories are included in the evaluation:

  • Attack Vector (AV): Network, Adjacent, Local or Physical
  • Attack Complexity (AC): Low or High
  • Privileges Required (PR): None, Low or High
  • User Interaction (UI): None or Required
  • Scope (S): Unchanged or Changed
  • Confidentiality Impact (C): None, Low or High
  • Integrity Impact (I): None, Low or High
  • Availability Impact (A): None, Low, or High

In the end, a criticality value of e.g. 4.2 or 5.3 is obtained according to mathematical calculation - and the various vulnerabilities can then be compared on the basis of these values or their remediation prioritized.

The CVSS is often requested by clients to have this comparability. In reality, however, the evaluation according to CVSS must be viewed critically. On the one hand, a subjective assessment still flows into the evaluation of the individual categories. On the other hand, the mathematical number at the end pretends to be granularly accurate, but has no significance at all (score of 4.1 vs 4.2 for example). In most cases, the clients then still carry out their own assessment, which leads the whole thing ad absurdum. We rather recommend carrying out a qualitative risk assessment right away in the first place.

Last modified: April 21, 2023

binsec GmbH
binsec GmbH is a consulting firm for information security and was founded in 2013 by security experts. Our team consists of experienced, certified specialists with different areas of expertise. Due to our extensive expertise in many different IT security fields, we can support our customers with a wide array of issues. Most of our customers are medium-sized companies, for whom security is pivotal to success.
Keywords