Get the App
SLTechnology News&Howtos  ›  IT Information  › 

FIRST releases General vulnerability scoring system version 4.0

Shulou Source: shulou.com Published: 2023-11-24 21:43:04 10月02日 Update

CTOnews.com November 2 News, incident response and Security team Forum (FIRST) today officially launched the CVSS 4.0 generic vulnerability scoring system, eight years after the 3.0 (last major version).

CTOnews.com Note: CVSS (Common Vulnerability Scoring System) is a standardized method for measuring the severity of software vulnerabilities, which scores vulnerabilities by multiple dimensions (such as attack complexity, scope of impact, etc.), thus providing a quantitative risk assessment tool for enterprises and organizations.

FIRST says:

The revised standard provides consumers with more refined basic indicators, eliminates the fuzziness of downstream scores, simplifies threat indicators, and improves the effectiveness of evaluating specific environmental safety requirements and compensation control.

In addition, several additional indicators for vulnerability assessment have been added, including automation (wormable), recovery (resiliency), value density, vulnerability response efforts, and provider urgency.

A key enhancement of CVSS v4.0 is the additional applicability to OT / ICS / IoT, adding safety metrics and values to supplementary and environmental indicator groups.

The new version also adds new naming methods, including Base (CVSS-B), Base + Threat (CVSS-BT), Base + Environmental (CVSS-BE), and Base + Threat + Environmental (CVSS-BTE).

Chris Gibson, CEO of FIRST, said:

The CVSS system has grown rapidly over the past 18 years, and each version is based on our ability to resist cybercrime. I am extremely proud of CVSS-SIG 's hard work and dedication to making version 4. 0.

As a membership organization, our goal is to empower our members and industries, demonstrate leadership, and ensure that we are committed to constantly improving the way we work together to protect people around the world from cyber attacks.

Tags: Vulnerabilities metrics versions scores security evaluation systems methods standards environment networks work attacks complexity effectiveness urgency pride continuity severity membership Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Linux Docker Shulou Information MariaDB Apple