• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
first announces cvss 4.0 new vulnerability scoring system

FIRST Announces CVSS 4.0 – New Vulnerability Scoring System

You are here: Home / General Cyber Security News / FIRST Announces CVSS 4.0 – New Vulnerability Scoring System
November 2, 2023

The Discussion board of Incident Reaction and Security Teams (Very first) has formally introduced CVSS v4., the upcoming technology of the Prevalent Vulnerability Scoring Technique conventional, additional than eight many years after the launch of CVSS v3. in June 2015.

“This most recent model of CVSS 4. seeks to provide the best fidelity of vulnerability evaluation for each industry and the public,” To start with stated in a statement.

CVSS in essence provides a way to capture the principal complex characteristics of a security vulnerability and generate a numerical score denoting its severity. The rating can be translated into different concentrations, this kind of as minimal, medium, superior, and critical, to assist corporations prioritize their vulnerability administration procedures.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


One of the main updates to CVSS v3.1, launched in July 2019, was to emphasize and clarify that “CVSS is intended to measure the severity of a vulnerability and must not be applied by itself to evaluate risk.”

Cybersecurity

CVSS v3.1 has also attracted criticism for a typical absence of granularity in the scoring scale and for failing to sufficiently symbolize health, human protection, and industrial management units.

The newest revision to the typical aims to handle some of these shortcomings by supplying quite a few supplemental metrics for vulnerability assessment, these as Basic safety (S), Automatable (A), Recovery (R), Price Density (V), Vulnerability Reaction Effort and hard work (RE), and Company Urgency (U).

It also debuts a new nomenclature to enumerate CVSS scores making use of a blend of Foundation (CVSS-B), Foundation + Danger (CVSS-BT), Foundation + Environmental (CVSS-BE), and Foundation + Risk + Environmental (CVSS-BTE) severity ratings.

The concept, To start with claimed, is to “strengthen the thought that CVSS is not just the Base rating,” introducing “this nomenclature should be utilized anywhere a numerical CVSS benefit is exhibited or communicated.”

“The CVSS Base Rating should be supplemented with an examination of the surroundings (Environmental Metrics), and with attributes that may perhaps modify around time (Risk Metrics),” it additional noted.

Found this write-up attention-grabbing? Comply with us on Twitter  and LinkedIn to read through much more exceptional material we put up.


Some areas of this posting are sourced from:
thehackernews.com

Previous Post: «hellokitty ransomware group exploiting apache activemq vulnerability HelloKitty Ransomware Group Exploiting Apache ActiveMQ Vulnerability
Next Post: Researchers Find 34 Windows Drivers Vulnerable to Full Device Takeover researchers find 34 windows drivers vulnerable to full device takeover»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.