Loading [MathJax]/extensions/MathMenu.js
Analysis of CVSS Vulnerability Base Scores in the Context of Exploits’ Availability | IEEE Conference Publication | IEEE Xplore

Analysis of CVSS Vulnerability Base Scores in the Context of Exploits’ Availability


Abstract:

Common Vulnerability Scoring System (CVSS) is a well-established standard for an evaluation of vulnerability criticality in Information and Communication Technology (ICT)...Show More

Abstract:

Common Vulnerability Scoring System (CVSS) is a well-established standard for an evaluation of vulnerability criticality in Information and Communication Technology (ICT) infrastructure. In this paper, a particular attention is given to selected aspects of the temporal component of the CVSS 3.x vector. An analysis was performed aimed at relating the information provided by the basic and temporal components of the CVSS 3.x vector using a public vulnerability database of known vulnerabilities, National Vulnerability Database (NVD) created and maintained by the National Institute of Standards and Technology (NIST), and two available publicly exploit databases: Exploit Database and Attacker KB. Histograms were derived from the information available in the databases using python scripts. The results obtained show that some numerical values of base scores obtained applying CVSS v3.x are overrepresented when compared with the respective numbers of available exploits.
Date of Conference: 02-06 July 2023
Date Added to IEEE Xplore: 08 August 2023
ISBN Information:

ISSN Information:

Conference Location: Bucharest, Romania

Funding Agency:


Contact IEEE to Subscribe

References

References is not available for this document.