SWEN-331: Engineering Secure Software Benjamin S Meyers
Common Vulnerability Scoring System
Engineering Secure Software
Last Revised: November 13, 2020 1
Common Vulnerability Scoring System Engineering Secure Software - - PowerPoint PPT Presentation
Common Vulnerability Scoring System Engineering Secure Software Last Revised: November 13, 2020 SWEN-331: Engineering Secure Software Benjamin S Meyers 1 How Bad is Bad? Weve seen many vulnerabilities Many of them can do catastrophic
SWEN-331: Engineering Secure Software Benjamin S Meyers
Last Revised: November 13, 2020 1
SWEN-331: Engineering Secure Software Benjamin S Meyers
2
SWEN-331: Engineering Secure Software Benjamin S Meyers
3
SWEN-331: Engineering Secure Software Benjamin S Meyers
4
AC: Attack Complexity AV: Attack Vector Confidentiality Impact
Exploitability Metrics Impact Metrics
PR: Privileges Required UI: User Interaction Integrity Impact Availability Impact Scope
SWEN-331: Engineering Secure Software Benjamin S Meyers
5
SWEN-331: Engineering Secure Software Benjamin S Meyers
6
SWEN-331: Engineering Secure Software Benjamin S Meyers
7
SWEN-331: Engineering Secure Software Benjamin S Meyers
8
SWEN-331: Engineering Secure Software Benjamin S Meyers
9
SWEN-331: Engineering Secure Software Benjamin S Meyers
10 10
SWEN-331: Engineering Secure Software Benjamin S Meyers
11 11
SWEN-331: Engineering Secure Software Benjamin S Meyers
12 12
SWEN-331: Engineering Secure Software Benjamin S Meyers
13 13
SWEN-331: Engineering Secure Software Benjamin S Meyers
14 14
SWEN-331: Engineering Secure Software Benjamin S Meyers
15 15
SWEN-331: Engineering Secure Software Benjamin S Meyers
16 16
SWEN-331: Engineering Secure Software Benjamin S Meyers
17 17
SWEN-331: Engineering Secure Software Benjamin S Meyers
18 18
SWEN-331: Engineering Secure Software Benjamin S Meyers
19 19
SWEN-331: Engineering Secure Software Benjamin S Meyers
20 20
SWEN-331: Engineering Secure Software Benjamin S Meyers
21 21
SWEN-331: Engineering Secure Software Benjamin S Meyers
22 22
SWEN-331: Engineering Secure Software Benjamin S Meyers
23 23
SWEN-331: Engineering Secure Software Benjamin S Meyers
24 24
SWEN-331: Engineering Secure Software Benjamin S Meyers
25 25
SWEN-331: Engineering Secure Software Benjamin S Meyers
26 26
SWEN-331: Engineering Secure Software Benjamin S Meyers
27 27
SWEN-331: Engineering Secure Software Benjamin S Meyers
28 28
SWEN-331: Engineering Secure Software Benjamin S Meyers
29 29
SWEN-331: Engineering Secure Software Benjamin S Meyers
30 30
Source: https://www.first.org/cvss/specification-document
SWEN-331: Engineering Secure Software Benjamin S Meyers
31 31
Source: https://www.first.org/cvss/specification-document
SWEN-331: Engineering Secure Software Benjamin S Meyers
32 32
SWEN-331: Engineering Secure Software Benjamin S Meyers
33 33
SWEN-331: Engineering Secure Software Benjamin S Meyers
34 34
SWEN-331: Engineering Secure Software Benjamin S Meyers
35 35