articleIEEE Security & PrivacyNov 1, 2006Closed access

Common Vulnerability Scoring System

National Institute of Standards and Technology · Carnegie Mellon University

Indexed incrossref

Abstract

Historically, vendors have used their own methods for scoring software vulnerabilities, usually without detailing their criteria or processes. This creates a major problem for users, particularly those who manage disparate IT systems and applications. The Common Vulnerability Scoring System (CVSS) is a public initiative designed to address this issue by presenting a framework for assessing and quantifying the impact of software vulnerabilities. Organizations currently generating CVSS scores include Cisco, US National Institute of Standards and Technology (through the US National Vulnerability Database; NVD), Qualys, Oracle, and Tenable Network Security. CVSS offers the following benefits: 1) standardized…

Citation impact

668
total citations
FWCI
33.66
Percentile
100%
References
1
Citations per year

Authors

3

Topics & keywords

Keywords
  • Vulnerability (computing)
  • Oracle
  • Computer science
  • Vulnerability management
  • Vulnerability assessment
  • Software
  • Computer security
  • Risk analysis (engineering)
No related works found for this paper.