logo

Infosec pros: We need CVSS, warts and all

ID: c22d01d6-321a-5dad-babd-42e992e21c36

STIX ID: report--c22d01d6-321a-5dad-babd-42e992e21c36

Feed Name: CyberScoop

Date Published: 2025-02-05

Date Updated: 2026-04-21

Author: Greg Otto

...
...

This article reviews debates over the Common Vulnerability Scoring System (CVSS), describing how NVD resource constraints and scoring practices have fueled criticism, while experts argue CVSS remains a useful, widely adopted baseline; it also surveys limitations of CVSS, complementary efforts such as EPSS for exploitation likelihood, and alternative frameworks (e.g., NCSC forgivability concepts), concluding that CVSS should continue as a cornerstone of vulnerability reporting when used alongside other tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.