What is a CVE?
The CVE definition is twofold. It stands for Common Vulnerabilities and Exposures, a list of publicly disclosed risks and vulnerabilities in software and systems. But CVE can also be used to reference a vulnerability that has been documented and assigned a number within the CVE list.
What is a CVE rating?
A CVE rating is a score between 1-10 that measures the severity of a vulnerability – how catastrophic the damage would be if a threat actor exploited a given vulnerability. CVE ratings are created based on standards in the Common Vulnerability Scoring System (CVSS), and are also referred to as CVSS scores.
What is the highest CVE rating?
CVE ratings, or CVSS scores, range from 1 to 10, with 10 indicating the most severe vulnerabilities. CVE ratings may also include temporal and environmental scores that reveal how available mitigations are for vulnerabilities and how widespread vulnerable systems are within an organization.
A CVSS score quantifies the severity of a vulnerability, guiding security teams in prioritizing patches and mitigations. The score falls into predefined ranges:
- 0.0 – None
- 0.1 – 3.9 – Low
- 4.0 – 6.9 – Medium
- 7.0 – 8.9 – High
- 9.0 – 10.0 – Critical
How CVE Ratings are Determined
The common vulnerability scoring system is based on several metrics. It begins with the severity of the vulnerability – in other words, how costly an attack that exploits the vulnerability would be in terms of impact on the organization and on the integrity and availability of systems. CVE ratings, or CVSS scores, also consider how easy it is for attackers to exploit the vulnerability and how easy a vulnerability is to remediate.
While these metrics are a good starting point for understanding the risk, CVSS scores are limited in three important ways:
- No real-time insight. There’s often a lag – sometimes as long as days or weeks – between the discovery of a vulnerability and until a CVSS rating is assigned. This leaves security teams in the dark as to how to prioritize a recently discovered vulnerability.
- Static scoring. Even though the level of risk changes over time as vulnerabilities are used with greater or lesser frequency, CVSS ratings rarely change. As a result, scores may not accurately reflect how prevalent certain vulnerabilities are in cyberattacks, or how easily they can be remediated after a period of time.
- No recognition of probability. The common vulnerability scoring system framework offers no insight into the intent of threat actors or the availability of an actual means to exploit the vulnerability in question, so scores do not reflect how likely a vulnerability is to be used in the near future.
What's the difference between CVE and CVSS?
CVE stands for Common Vulnerabilities and Exposures, a list of known vulnerabilities in software and systems. CVSS is the Common Vulnerability Scoring System, an open framework for determining the severity of vulnerabilities on the CVE list.
The flaws in the traditional CVE rating system
CVE, or Common Vulnerabilities and Exposures, is a list of publicly disclosed flaws in software and systems that hackers can exploit. CVE ratings are determined by the Common Vulnerability Scoring System (CVSS), which assigns a CVE rating or score between 1 (low) and 10 (high) based on the severity of particular vulnerability. Because the number of new vulnerabilities outpaces the resources of IT teams to patch them, CVE ratings are intended to help identify the vulnerabilities that pose the greatest risk, allowing security teams to address them first.
However, CVE ratings (or CVSS scores), are flawed in three serious ways that prevent security teams from getting an accurate read on which vulnerabilities represent the greatest risk.
A rating lag
While some vulnerabilities receive a CVE rating quickly, others may not be scored for weeks. This prevents security teams from having a complete picture of the risks posed by vulnerabilities.
A static score
Once a CVSS score is assigned, it rarely changes, even when vulnerabilities that were once seldom used become highly popular with attackers.
No recognition of intent
This is the most significant flaw in the traditional CVSS and CVE rating system. Traditional CVE ratings don’t evaluate the probability that threat actors will exploit a given vulnerability. They don’t take into account the way that cyber criminals are talking about vulnerabilities, how often they’re buying and selling tools to exploit them, or the volume of information that’s currently being shared about how to use them in attacks.
As a result of these flaws, traditional CVE ratings can’t provide security teams with the insights they need to make accurate decisions about vulnerability management. That’s where Bitsight DVE Intelligence can transform assessment and prioritization efforts.