Authors
Karen Scarfone, Peter Mell
Publication date
2009/10/15
Conference
2009 3rd International Symposium on Empirical Software Engineering and Measurement
Pages
516-525
Publisher
IEEE
Description
The Common Vulnerability Scoring System (CVSS) is a specification for measuring the relative severity of software vulnerabilities. Finalized in 2007, CVSS version 2 was designed to address deficiencies found during analysis and use of the original CVSS version. This paper analyzes how effectively CVSS version 2 addresses these deficiencies and what new deficiencies it may have. This analysis is based primarily on an experiment that applied both version 1 and version 2 scoring to a large set of recent vulnerabilities. Theoretical characteristics of version 1 and version 2 scores were also examined. The results show that the goals for the changes were met, but that some changes had a negligible effect on scoring while complicating the scoring process. The changes also had unintended effects on organizations that prioritize vulnerability remediation based primarily on CVSS scores.
Total citations
201020112012201320142015201620172018201920202021202220232024312714142514141517232223177
Scholar articles
K Scarfone, P Mell - 2009 3rd International Symposium on Empirical …, 2009