Feed abonnieren

The Common Vulnerability Scoring System (CVSS) is well known in the world of product security, development and IT. “The Common Vulnerability Scoring System provides a way to capture the principal characteristics of a vulnerability and produce a numerical score reflecting its severity,” per FIRST’s definition.

In layman’s terms, CVSS is used to assign a common score to a discovered vulnerability to let people know, at a glance, how technically severe the vulnerability is and to provide vendors a starting point for assessing the risk of a vulnerability towards their product.

There are a number of scoring systems used across the industry, but CVSS is one of the most prominent and is used by Red Hat and many other organizations. Red Hat has long served as a contributor to the CVSS Special Interest Group (SIG) which is responsible for the creation, updating and support of the standard. The current version of the CVSS standard that is being used is version 3.1.

At FIRST.org’s 35th Annual FIRST Conference in early June 2023, it was announced that CVSS version 4.0 is ready for feedback from a wider audience. Major changes from v3.1 to v4.0 include the introduction of additional supplemental metrics, an increased focus on safety’s effect on a vulnerability, and increased clarity and granularity for many of the existing metrics and overall score. Please view FIRST’s announcement page for a complete list of the changes.

On behalf of the CVSS SIG, we invite all of our partners and associates to test out the new calculator, review the specification documents and submit your feedback! The SIG would greatly appreciate hearing from as many CVSS users as possible so the standard can best reflect the needs of the CVSS community.

Resources for the new standard, including a mock calculator and guidance documentation, can be found on FIRST’s official CVSS v4.0 Public Preview information page.

Additional resources


Über den Autor

Austin Kimbrell began working at Red Hat in 2021, but his interest in networking and security stems back to college, where he majored in Computer Science concentrating on Networking and Security. He has worked as a developer, evaluator and product security engineer since 2014 when he had his first co-op internship and graduated in 2015 from University of the Pacific.

Read full bio
UI_Icon-Red_Hat-Close-A-Black-RGB

Nach Thema durchsuchen

automation icon

Automatisierung

Das Neueste zum Thema IT-Automatisierung für Technologien, Teams und Umgebungen

AI icon

Künstliche Intelligenz

Erfahren Sie das Neueste von den Plattformen, die es Kunden ermöglichen, KI-Workloads beliebig auszuführen

open hybrid cloud icon

Open Hybrid Cloud

Erfahren Sie, wie wir eine flexiblere Zukunft mit Hybrid Clouds schaffen.

security icon

Sicherheit

Erfahren Sie, wie wir Risiken in verschiedenen Umgebungen und Technologien reduzieren

edge icon

Edge Computing

Erfahren Sie das Neueste von den Plattformen, die die Operations am Edge vereinfachen

Infrastructure icon

Infrastruktur

Erfahren Sie das Neueste von der weltweit führenden Linux-Plattform für Unternehmen

application development icon

Anwendungen

Entdecken Sie unsere Lösungen für komplexe Herausforderungen bei Anwendungen

Original series icon

Original Shows

Interessantes von den Experten, die die Technologien in Unternehmen mitgestalten