Reporting and Communication Flashcards

1
Q

CVSS scoring 0-10

A

CVSS score between 9 and 10 - Critical

CVSS score between 7 and 8.9 - High

CVSS score between 4 and 6.9 - Medium

CVSS score between 0.1 and 3.9 - Low

CVSS score 0 - None

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

CVSS Base Group

A

The CVSS base group defines exploitability metrics that measure how the vulnerability can be exploited, as well as impact metrics that measure the impact on confidentiality, integrity, and availability. The Exploitability metrics include the following:

Attack Vector (AV) represents the level of access an attacker needs to have to exploit a vulnerability. It can assume four values:
    Network (N)
    Adjacent (A)
    Local (L)
    Physical (P)
Attack Complexity (AC) represents the conditions beyond the attacker’s control that must exist in order to exploit the vulnerability. The values can be the following:
    Low (L)
    High (H)
Privileges Required (PR) represents the level of privileges an attacker must have to exploit the vulnerability. The values are as follows:
    None (N)
    Low (L)
    High (H)
User Interaction (UI) captures whether a user interaction is needed to perform an attack. The values are as follows:
    None (N)
    Required (R)
Scope (S) captures the impact on systems other than the system being scored. The values are as follows:
    Unchanged (U)
    Changed (C)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly