Is Vulnerability Report Confidence Redundant? Pitfalls Using Temporal Risk Scores
François Boechat, Gabriel Ribas, Lucas Senos, Miguel Angelo Santos Bicudo, Mateus Nogueira, Leandro Pfleger de Aguiar, Daniel Sadoc Menasché · IEEE Security & Privacy · 2021
The Common Vulnerability Scoring System score is the de facto standard to assess risk of software vulnerabilities, with three temporal components: exploitability, remediation level, and report confidence. We discuss how the latter may be inferred from the first two, pointing practical and conceptual issues in the usage of temporal risk scores.