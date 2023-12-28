The Forum of Incident Response and Security Teams (FIRST) officially launched the fourth version of the Common Vulnerability Scoring System (CVSS 4.0), in November 2023.

CVSS 4.0, the industry standard for assessing the severity of computer system security vulnerabilities, is a significant update from the previous versions of the CVSS and brings several changes that will impact how organizations assess and prioritize vulnerabilities.

In this article, we will take a closer look at all the standards used to register and track software vulnerabilities and the scoring systems to assess their criticality.

What is a Software Vulnerability?

In computer science, vulnerabilities are flaws or glitches that weaken a system's overall security. Vulnerabilities can be weaknesses in either the hardware itself or the software that runs on it.

Vulnerabilities can be exploited by threat actors to obtain privilege access levels, either by leveraging a flaw to gain unauthorised access or by exploiting a loophole that has been missed out by the software development team to gain access that appears to be authorised.

Vulnerability scanning is the process of identifying security weaknesses and flaws in systems and software running on them. This is an integral component of a vulnerability management programme, which has one overarching goal – to protect the organisation from breaches and the exposure of sensitive data.

How Does the CVE System Work?

The Common Vulnerabilities and Exposures (CVE) system lists publicly known information security vulnerabilities and exposures.

It was founded in 1999 by the MITRE Corporation in collaboration with the US Department of Homeland Security (DHS) and the US Cybersecurity and Infrastructure Security Agency (CISA).

Each entry in the CVE list is assigned a unique CVE identifier, a four-part identifier consisting of the year the vulnerability was discovered and a sequential number.

For example, the CVE identifier for the recent Citrix Bleed vulnerability is CVE-2023-4966.

Additionally, a CVE entry includes some essential information about the vulnerability for managing information security risks. These include:

A description of the vulnerability, which includes information such as the affected software, the potential impact of the vulnerability, and the mitigation steps

A severity score, based on the potential impact of the vulnerability if it is exploited

References to other sources of information

By using the CVE system, organizations can identify, prioritize and mitigate vulnerabilities.