cognitive cybersecurity intelligence

News and Analysis

Search

CVSS system criticized for failure to address real-world impact

Cybersecurity company JFrog has argued that the Common Vulnerability Scoring System (CVSS) needs a complete overhaul due to overhyped vulnerability ratings. In a new report, the firm contends that the CVSS metrics often provide an oversimplified view of security risks. JFrog’s review of the top 50 Common Vulnerabilities and Exposures suffered in 2022 revealed that JFrog gave 64% a lower severity rating. The company maintains that lack of context and overly complex assessments misdirect action and can result in priority vulnerabilities being ignored.

Source: portswigger.net –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts