ARTICLE
CVSS (Common Vulnerability Scoring System ) Version 2.0 released
Wednesday 20 June 2007
The Common Vulnerability Scoring System (CVSS) provides an open framework for communicating the characteristics and impacts of IT vulnerabilities. CVSS consists of 3 groups: Base, Temporal and Environmental.Each group produces a numeric score ranging from 0 to 10, and a Vector, a compressed textual representation that reflects the values used to derive the score.
The Base group represents the intrinsic qualities of a vulnerability.
The Temporal group reflects the characteristics of a vulnerability that change over time. The Environmental group represents the characteristics of a vulnerability that are unique to any user’s environment.
CVSS enables IT managers, vulnerability bulletin providers, security vendors, application vendors and researchers to all benefit by adopting this common language of scoring IT vulnerabilities.
POSTSCRIPTUM
RELATED ARTICLES
CVSS, Framework, Methodology, Metrics,
30 January 2008 : CVSS V2.0 Web based calculator released
20 June 2007 : CVSS (Common Vulnerability Scoring System ) Version 2.0 released
Security Dashboard





