News: 1610098210

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

How good are you at scoring security vulnerabilities, really? Boffins seek infosec pros to take rating skill survey

(2021/01/08)


A German academic is running a study into the effectiveness of vulnerability scores – and is hoping the research will shed more light on the occasionally controversial system.

By running a survey on whether infosec bods think the Common Vulnerability Scoring System (CVSS) is a useful tool for assessing security flaws, Dr Zinaida Benenson of Friedrich-Alexander Universität Erlangen-Nürnberg's IT Security Infrastructure Lab in Germany hopes to further the infosec world's understanding of how reliable the system really is.

[1]

While the survey hopes to gain up to 300 respondents, Benenson was coy about precisely what she's hoping to prove or disprove, but she did drop The Register a hint about the current state of CVSS scoring.

In preliminary research, Benenson and her fellow researchers asked a handful of infosec bods to allocate CVSS scores to 10 sample vulnerabilities, as a way of testing how consistent their scoring was.

"I'm not naming the vulnerabilities, because some of them are now in the survey, but just to give you a feeling..." she said, sending us a partial table of scores from that exercise: vuln 1: 4.7, 5.4, 6.1, 6.3, 7.3, 7.5

vuln 2: 3.0, 4.8, 5.0, 5.4, 6.5, 7.1, 7.6, 8.4

vuln 3: 4.7, 6.8, 7.2, 8.2, 9.0, 9.8

[...]

vuln 7: 3.1, 4.2, 4.8, 5.3, 6.5, 7.5, 8.3, 9.3

[...]

vuln 10: 0.0., 3.7, 5.3, 8.2, 8.8

"Some of the scores were of course the same for different experts, but on the whole, there wasn't much agreement," Benenson added. "And I'm not picking especially weird vulnerabilities, all 10 of them were rated like this."

The CVSS survey can be [2]found here .

CVSS was [3]invented in 2005 when Cisco, Microsoft, Qualys, Symantec and others joined forces to announce the scoring system we all know and, er, love. In the decade-and-a-half since then, CVSS has become the standard at-a-glance measure of a given vulnerability's severity, with the worst reaching 10.0 on the system's ten-point scoring scale.

Scores are commonly allocated to vulnerabilities along with a Common Vulnerabilities and Exposure (CVE) number, which has led to the undesirable practice of researchers "collecting" high-severity CVEs by [4]using dubious methods .

A recent example of a 10.0-rated CVEs was a VMware vCenter vuln that [5]allowed anyone at all to remotely create an admin-level account . Lower down the scale, but still significant, was [6]a CVSS 7.8-graded flaw in ConnectWise's Automate product that allowed someone with user credentials to remotely run commands on an Automate instance.

[7]

Referring to the table of varied CVSS scores she showed us, Benenson said: "We are not saying that CVSS experts are not skilful. We are trying to find factors behind the fact that the scores are so different. Actually, the scores are supposed to be the same across different actors; this is the idea of CVSS." ®

Get our [8]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x250%7C300x252%7C300x600&tile=3&c=33X-g7ReCygmxTvopABaKLOwAAAA0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dtop%26test%3D0

[2] https://user-surveys.cs.fau.de/index.php?r=survey/index&sid=248857

[3] https://www.theregister.com/2005/02/23/cvss/

[4] https://www.theregister.com/2019/03/08/thales_topseries_vuln/

[5] https://www.theregister.com/2020/04/17/vmware_vcenter_critical_vuln_anyone_create_admin_users/

[6] https://www.theregister.com/2020/06/12/connectwise_security/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x100%7C300x250%7C300x251&tile=4&c=44X-g7ReCygmxTvopABaKLOwAAAA0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://whitepapers.theregister.com/

claimed

So there are ~99 different scores, right, from 0.0 to 10.0? Surely there are more than 99 different ways for people to screw up code. So we'll always see a 'bucket' effect, and on top of that how are you to cross reference those. Its a hard problem, no wonder there is variance.

Bucket effect

steven_t

The bucket effect is expected. The scoring system is designed to be an assessment the severity of an issue so, obviously, different types of issues with similar severities ought to end up with the same score.

I don't generally use the CVSS score on its own. It is worked out from other metrics, such as Access Vector and Confidentiality Impact, and I find these really useful for deciding what the potential risk is to our systems.

We once had a security audit from a firm that ranked their results as Critical, High, Medium and Low with absolutely no consistency as to how they chose the severity. They ranked nearly everything, even things with no actual security impact, as Critical or High, and would not justify that decision. CVSS is far, far better than that arbitrary system. It isn't perfect, however, as the article explains.

Re: Bucket effect

Halfmad

I agree, CVSS is generally one of several factors to be considered. I always take it as a starting point then look at how that particular vulnerability could/can impact the business.

I've seen some vulnerabilities scored in the low 6s which could have impacted us far higher than many of the routine types scoring 9+ due to how the business operated.

Anyone relying solely on the CVSS score needs to rethink their processes. It's purely a generalised indicator.

Once there was this conductor see, who had a bass problem. You see, during
a portion of Beethovan's Ninth Symphony in which there are no bass violin
parts, one of the bassists always passed a bottle of scotch around. So,
to remind himself that the basses usually required an extra cue towards the
end of the symphony, the conductor would fasten a piece of string around the
page of the score before the bass cue. As the basses grew more and more
inebriated, two of them fell asleep. The conductor grew quite nervous (he
was very concerned about the pitch) because it was the bottom of the ninth;
the score was tied and the basses were loaded with two out.