logo

CVSS Scores Are Dead. Let’s Explore 4 Alternatives

Conference:  RSA Conference 2021

2021-05-17

Abstract

If a picture is worth a thousand words, then a CVSS score is worth two hundred and fifty. Join this session to explore the limitations of CVSS scores and the benefits of a risk-based approach to vulnerability scoring which factors in availability of exploits, patches, and scale of deployments. The session will wrap-up with pros and cons of the alphabet soup of options: EPSS, SSVC, VPR and more.

Materials:

Tags:

Post a comment

Related work


Conference:  RSA Conference 2023
Authors: Brian Russell, Naveen Srinivasan
2023-04-24



Authors: Sophie Wigmore, Frankie Gallina-Jones
2022-10-28

Authors: Dejan Bosanac, Steve Wong, Kilton Hopkins
2021-10-13