The bogus CVE problem
The bogus CVE problem
Posted Sep 15, 2023 1:22 UTC (Fri) by amworsley (subscriber, #82049)Parent article: The bogus CVE problem
I think it would be good to see some better CVSS rules established.
e.g. no CVSS 10 (or > 8?) if there is no PoC exploit code. So much time is wasted trying to see
if a vaguely described fault is actually a significant problem. If there is a PoC it really spells out
what is required and what can be done very quickly and efficiently.
e.g. no CVSS 10 (or > 8?) if there is no PoC exploit code. So much time is wasted trying to see
if a vaguely described fault is actually a significant problem. If there is a PoC it really spells out
what is required and what can be done very quickly and efficiently.
