Chapter 4 Analyzing Vulnerability Scans Flashcards
An industry standard for assessing the severity of security vulnerabilities - Provides a technique for scoring each vulnerability on a variety of measures
Common Vulnerability Scoring System (CVSS)
Describes how an attacker would exploit a vulnerability
Access Vector Metric
CVSS access vector metric
The attacker must have physical or logical access to the affected system
Score 0.395
Local (L)
CVSS access vector metric
The attacker must have access to the local network that the affected system is connected to
Score 0.646
Adjacent Network (A)
CVSS access vector metric
The attacker can exploit a vulnerability remotely over a network
Score 1.000
Network (N)
Describe the difficulty of exploitng the vulnerability
Access Complexity Metric
CVSS access complexity metric
Exploiting the vulnerability requires “specialized” conditions that would be difficult to find
Score 0.350
High (H)
CVSS access complexity metric
Exploiting the vulnerability requires “somewhat specialized” conditions
Score 0.610
Medium (M)
CVSS access complexity metric
Exploiting the vulnerability does not require any specialized conditions
Score 0.710
Low (L)
Describes the authentication hurdles that an attacker would need to clear to exploit a vulnerability
Authentication Metric
CVSS authentication metric
Attackers would need to authenticate two or more times to exploit the vulnerability
Score 0.450
Multiple (M)
CVSS authentication metric
Attackers would need to authenticate once to exploit the vulnerability
Score 0.560
Single (S)
CVSS authentication metric
Attackers do not need to authenticate to exploit the vulnerability
Score 0.704
None (N)
Describe the type of information disclosure that might occur if an attacker successfully exploit their vulnerability
Confidentiality Metric
CVSS confidentiality metric
There is no confidentiality impact
Score 0.000
None (N)
CVSS confidentiality metric
Access to some information is possible, but the attacker does not have control over what information is compromised
Score 0.275
Partial (P)
CVSS confidentiality metric
All information on the system is compromised
Score 0.660
Complete (C)
Describes the type of information alteration that might occur if attacker successfully exploit vulnerability
Integrity Metric