←back to thread

174 points andy99 | 1 comments | | HN request time: 0s | source
Show context
tptacek ◴[] No.43604427[source]
Broken record, but "has a CVSS score of 10.0" is literally meaningless. In fact, over the last couple years, I've come to take vulnerabilities with very high CVSS scores less seriously. Remember, Heartbleed was a "7.5".
replies(5): >>43604810 #>>43605410 #>>43606314 #>>43609363 #>>43610358 #
b8 ◴[] No.43606314[source]
A new scoring system should be made that is a better signal.
replies(2): >>43606373 #>>43606374 #
tptacek ◴[] No.43606373[source]
I think the original one did just fine: "info, low, medium, high, crit".

I could even do without "crit".

replies(1): >>43606709 #
worthless-trash ◴[] No.43606709[source]
I believe companies often call that the flaws impact.

It is different than the cvss rating.

replies(1): >>43606866 #
tptacek ◴[] No.43606866[source]
In that it is meaningful, yes.
replies(1): >>43609087 #
1. worthless-trash ◴[] No.43609087[source]
Surely you think AV:P has a meaningful description in the CVSS Score ?