Opinion: We need a way to talk about Cyber Physical Risk
ID: 257f4e73-a716-5c9c-8cf0-f49a8abfe052
STIX ID: report--257f4e73-a716-5c9c-8cf0-f49a8abfe052
Feed Name: Security Ledger
Threat Score
The article compares two recent vulnerabilities — a critical PrinterLogic origin-validation flaw (CVE-2018-5409) and a medium-rated GE anesthesia machine authentication flaw (CVE-2019-10966) — to illustrate how CVSS base scores can misrepresent real-world cyber-physical risk; it argues current scoring overlooks physical safety consequences (including potential lethal outcomes) and calls for a unified vulnerability/risk rating approach that incorporates cyber-physical impacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
