What is the CVSS se...
 
Notifications
Clear all

What is the CVSS severity level of the vulnerability discovered by Sam in the above scenario?

1 Posts
1 Users
0 Likes
157 Views
(@rippesteban)
Posts: 727
Noble Member
Topic starter
 

Sam is working as a system administrator In an organization. He captured the principal characteristics of a vulnerability and produced a numerical score to reflect Its severity using CVSS v3.0 to property assess and prioritize the organization's vulnerability management processes. The base score that Sam obtained after performing cvss rating was 4.0.

What is the CVSS severity level of the vulnerability discovered by Sam in the above scenario?

  • A . Medium
    B. Low
    C. Critical
    D. High

Show Answer Hide Answer

Suggested Answer: A

Explanation:

Rating CVSS Score

None 0.0

Low 0.1

- 3.9

Medium 4.0

- 6.9

High 7.0

- 8.9

Critical 9.0

- 10.0

https://www.first.org/cvss/v3.0/specification-document

The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of software vulnerabilities. CVSS consists of three metric groups: Base, Temporal, and Environmental. The Base metrics produce a score ranging from 0 to 10, which can then be modified by scoring the Temporal and Environmental metrics. A CVSS score is also represented as a vector string, a compressed textual representation of the values used to derive the score. Thus, CVSS is well suited as a standard measurement system for industries, organizations, and governments that need accurate and consistent vulnerability severity scores. Two common uses of CVSS are calculating the severity of vulnerabilities discovered on one's systems and as a factor in prioritization of vulnerability remediation activities. The National Vulnerability Database (NVD) provides CVSS scores for almost all known vulnerabilities.

Qualitative Severity Rating Scale

For some purposes, it is useful to have a textual representation of the numeric Base, Temporal and Environmental scores.

Table

Description automatically generated

 
Posted : 16/02/2023 12:06 am
Topic Tags

Latest EC-Council 312-50v12 Dumps Valid Version

Latest And Valid Q&A | Instant Download | Once Fail, Full Refund
Share: