Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Improving the Common Vulnerability Scoring System

Published

Author(s)

Peter M. Mell, Karen A. Scarfone

Abstract

The Common Vulnerability Scoring System is an emerging standard for scoring the impact of vulnerabilities. This paper presents the results of our analysis of the scoring system and the results of our experiment scoring a large set of vulnerabilities using the standard. While the scoring system was found to be useful, it contains a variety of deficiencies that limit its ability to measure the impact of vulnerabilities. We demonstrate how these deficiencies could be addressed in subsequent versions of the standards and how these changes can be backwards-compatible with existing scoring efforts.
Citation
Institution of Engineering and Technology (IET) Information Security

Citation

Mell, P. and Scarfone, K. (2007), Improving the Common Vulnerability Scoring System, Institution of Engineering and Technology (IET) Information Security, [online], https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=51124 (Accessed December 6, 2024)

Issues

If you have any questions about this publication or are having problems accessing it, please contact reflib@nist.gov.

Created September 28, 2007, Updated February 17, 2017