No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

CVSS 4.0 Is Here, But Prioritizing Patches Still a Hard Problem

July 22, 2023
in Protection
0
Exposure Management Looks to Attack Paths, Identity to Better Measure Risk



The soon-to-be-released Version 4.0 of the Common Vulnerability Scoring System (CVSS) promises to fix a number of issues with the severity metric for security bugs. But vulnerability experts say that prioritizing patches or measuring exploitability will still be a tough nut to crack.

The Forum of Incident Response and Security Teams (FIRST) released a preview of the next version of the CVSS last week at its annual conference. Version 4 will do away with the vague “temporal” metric, replacing it with the more descriptive “threat” metric and it will add other factors to the base metric calculation. The changes improve the overall usability of CVSS, according to FIRST, which added that companies and organizations can try the metric for grading current vulnerabilities and provide feedback prior to the launch of the general release.

CVSS 4 adds two new factors for companies to use in calculating the base metric: Attack Requirements (AT) and User Interaction (UI), measuring the complexity of the attack and whether an attack requires user interaction, according to a description of the new specification. In addition, a component of the CVSS is the environmental score, which is company-specific and measures the impact a vulnerability can have on their IT environment.

“[T]his latest release marks a significant step forward with added capabilities crucial for teams with the importance of using threat intelligence and environmental metrics for accurate scoring at its core,” FIRST said in a statement on the preview release of CVSS 4.

Patch Prioritization Needs More than CVSS

A better Common Vulnerability Scoring System could give companies a better approach to deciding which vulnerabilities should receive priority for patching, but it shouldn’t be seen as a panacea, say experts.

When it comes to determining exploitability, one of the biggest metrics that organizations use to prioritize patches, companies have a number of tools. They can use the CVSS, the Known Exploited Vulnerability (KEV) list from the US Cybersecurity and Infrastructure Security Agency (CISA), the Exploit Predication Scoring System (EPSS), or other proprietary systems, such as the Coalition Exploit Scoring System. Yet, any approach has to match an organizations’ capabilities and resources, says Sasha Romanosky, a senior policy researcher with RAND Corp., a global policy and research think tank.

“The issue is not so much [which approach], but the strategy one uses that produces the best — that is, prioritized — list for their organization,” says Romanosky, a contributor to both CVSS and EPSS. “We’ve come to learn that CVSS is not a good predictor of threat — exploitation — [on its own, and] that was a tough pill for us, the creators [of] CVSS, to swallow, but it’s the reality.”

Knowing the systems that are part of an organization’s attack surface area, for example, is critical, says Dustin Childs, head of threat awareness for Trend Micro’s Zero Day Initiative (ZDI).

“One thing I always recommend is to be ruthless in your asset discovery and understand which systems are key to your business,” he says. “That will help prioritization.”

CVSS Timing, Complexity Challenges

The new CVSS still faces hurdles when it comes to providing actionable assessments for prioritization. For instance, exploitability metrics also need to be generated quickly, so that organizations have guidance as soon as possible for making decisions over prioritizing patching, says Scott Walsh, a senior security researcher at Coalition, an active-protection cyber-insurance firm.

“When a new CVE is announced, risk managers and defenders may turn to the CVSS or the EPSS for severity and exploitability scores, but these industry-standard systems often take time to score new CVEs — anywhere from a week to up to a month,” he says. “During this time, organizations don’t always know which vulnerabilities have the highest potential to negatively affect their individual digital ecosystems and technologies.”

In addition, the latest CVSS can be complex to decipher, with nearly two dozen attributes used to calculate the base metric — complexity that could hinder security teams’ ability to gauge their risk.

“These variables will require multiple business units to agree upon the impacts and requirements,” he says. “In security, time is of the essence, and quickly responding can be the difference between successfully preventing an attack or being a victim. These variables make the vulnerability evaluation process slow and cumbersome when responding to a new threat.”

Editorial Team

Editorial Team

Related Posts

This 16-Inch Stacked, Portable Second Monitor Is On Sale for $280 Right Now
Protection

This 16-Inch Stacked, Portable Second Monitor Is On Sale for $280 Right Now

April 3, 2026
The JBL Charge 6 Speaker Is $90 Off Right Now
Protection

The JBL Charge 6 Speaker Is $90 Off Right Now

April 3, 2026
The Apple MagSafe Duo Charger Is Over $50 Off Right Now
Protection

The Apple MagSafe Duo Charger Is Over $50 Off Right Now

April 3, 2026
This Unlocked Motorola Razr+ Is Over $600 Off Right Now
Protection

This Unlocked Motorola Razr+ Is Over $600 Off Right Now

April 3, 2026
How (and Why) to Do Copenhagen Planks
Protection

How (and Why) to Do Copenhagen Planks

April 3, 2026
3 Reasons to Refinance Your Auto Loan with Autopay
Protection

3 Reasons to Refinance Your Auto Loan with Autopay

April 2, 2026
Load More
Next Post
Dow Jones Futures: Market Rally Still Healthy; Watch These 3 Stocks

Dow Jones Futures: Market Rally Still Healthy; Watch These 3 Stocks

Popular News

  • Ich habe meine Haare radikal gekürzt & fühle mich frei

    Ich habe meine Haare radikal gekürzt & fühle mich frei

    0 shares
    Share 0 Tweet 0
  • The 10 best banks for college students in 2025

    0 shares
    Share 0 Tweet 0
  • Gasoil is spiking more than crude. What it is and why prices are soaring amid Iran conflict

    0 shares
    Share 0 Tweet 0
  • A billionaire investor who predicted the ’08 crisis and the post-COVID inflation spike sees ‘significant’ recession risk and a prolonged period of low asset returns

    0 shares
    Share 0 Tweet 0
  • Crypto Fund Inflows Top $47.2B as Bitcoin Trails

    0 shares
    Share 0 Tweet 0

Latest News

XRP ETF “supply shock” fears face pushback as on-chain data shows 16B on CEXs

RootData’s project claiming feature lifts transparency scores and traffic

April 3, 2026
0

RootData’s project claiming lets teams verify and manage profiles, lifting transparency scores over 30% and driving a 220% jump in...

Recruiting Experience Manager (294) - HigherEdJobs

Recruiting Experience Manager (294) – HigherEdJobs

April 3, 2026
0

Job DescriptionThe Recruiting Experience Manager is an integral part of Freeman's Career Management Center whose focus is on increasing high-impact...

Aaaargh! Trump’s new budget hikes spending by $1 trillion over 2025.

Aaaargh! Trump’s new budget hikes spending by $1 trillion over 2025.

April 3, 2026
0

And those promised ‘DOGE’ savings? Just $73 billion.

This 16-Inch Stacked, Portable Second Monitor Is On Sale for $280 Right Now

This 16-Inch Stacked, Portable Second Monitor Is On Sale for $280 Right Now

April 3, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.