|
|
|
|
|
by tsujamin
841 days ago
|
|
CVSS as practiced sucks sometimes, the rules around not chaining vulnerabilities to up a score are rarely followed, but as specified it’s actually a good system. Undercutting my own point though, it doesn’t hurt to rerun a calculation if you think the public vectors is “lacking” or if temporal/environmental metrics matter in your context |
|
I feel like I'm on reasonably safe ground when I say that my take on CVSS is a mainstream one in the field.