|
|
Log in / Subscribe / Register

The bogus CVE problem

The bogus CVE problem

Posted Sep 15, 2023 1:22 UTC (Fri) by amworsley (subscriber, #82049)
Parent article: The bogus CVE problem

I think it would be good to see some better CVSS rules established.
e.g. no CVSS 10 (or > 8?) if there is no PoC exploit code. So much time is wasted trying to see
if a vaguely described fault is actually a significant problem. If there is a PoC it really spells out
what is required and what can be done very quickly and efficiently.


to post comments

The bogus CVE problem

Posted Sep 15, 2023 10:01 UTC (Fri) by farnz (subscriber, #17727) [Link]

That sort of thing is already captured by the "Exploit Code Maturity (E)" component of the CVSS score; if the overall score was capped to 4 if E:U or E:X (i.e. no PoC available now), then people would focus on that.

Organisations that consume the CVSS metrics can do that today, of course.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds