Hacker News new | ask | show | jobs
by Sebguer 1639 days ago
The third CVE arbitrarily had a score of ~7.5 despite requiring a non-standard configuration and only enabling a denial of service attack. The preceding CVE with the same outcome only warranted a 3.5, until it was shown to also potentially allow an RCE. CVSS is honestly pretty open to interpretation, since it's not a particularly objective set of measures.
1 comments

Fair enough, I agree with you there. CVSS(v2/v3) can be subjective and can change when new information comes to light.