Rethinking CVEs: Are CVSS Scores Fit for Purpose?

Are Common Vulnerability Scores Misleading? Experts Call for Cybersecurity System Overhaul

Is your organization placing too much faith in vulnerability scores? Cybersecurity experts are questioning the very foundation upon which many organizations assess and mitigate risk. Aram Hovespyan, co-founder and CEO of Codific, argues that the current systems for identifying security vulnerabilities and assessing threat risk, particularly the CVE and CVSS frameworks, are flawed and in need of serious reform. He contends that a significant portion of Common Vulnerabilities and Exposures (CVEs) are essentially meaningless, leading to wasted resources and potentially misdirected security efforts. This article will delve into the criticisms, exploring the problems with CVE assignments, the inconsistencies of CVSS scores, and potential alternative approaches to vulnerability management.

The Problem with CVEs: Are They Meaningless?

The core of Hovespyan’s argument lies in the assertion that a substantial percentage of CVEs are either unconfirmed or disputed, rendering them practically useless.

Unconfirmed and Disputed Vulnerabilities

Hovespyan’s claim is supported by academic research presented at the USENIX Security Symposium. The paper, “Confusing Value with Enumeration: Studying the Use of CVEs in Academia,” analyzed 1,803 CVEs cited in research papers over a five-year period. The startling conclusion? A full 34% of these CVEs lacked public confirmation or were actively disputed by the maintainers of the affected software projects. This raises serious questions about the validity and reliability of CVEs as indicators of real-world risk.

Consider the implications: security teams are spending time and resources investigating and patching vulnerabilities that may not even exist, diverting attention from genuine threats. This also pollutes vulnerability databases and potentially leads to alert fatigue.

Misaligned Incentives in CVE Assignment

The process of assigning CVEs is also fraught with potential issues, stemming from misaligned incentives among the various parties involved.

The CVE assignment process begins when a security researcher reports a potential vulnerability to a CVE Numbering Authority (CNA). Originally, MITRE was the sole CNA, but now numerous organizations, including Microsoft, can assign CVEs. CNAs are responsible for verifying the vulnerability, assigning a CVE number, and publishing the details.

However, as Hovespyan points out, the motivations of these CNAs can vary significantly:

  • Vulnerability Researchers: Often driven by a desire to build their reputations, researchers may be incentivized to report as many CVEs as possible, regardless of their actual impact.
  • Product CNAs: Companies are often reluctant to create CVEs that expose flaws in their own products, potentially leading to underreporting.
  • CNA Last Resorts (CNA-LRs): These organizations, such as Red Hat, are authorized to assign CVEs on behalf of other CNAs. However, Hovespyan argues that they often lack the necessary technical context and are more focused on speed than accuracy.

This complex web of incentives can lead to the proliferation of low-quality or inaccurate CVEs, creating unnecessary work for developers and security professionals.

The Impact on Developers

Ultimately, it’s the developers who bear the brunt of these problems. They are forced to deal with a constant barrage of vulnerability reports, many of which are difficult to dispute, even if they are inaccurate or invalid. This can be a significant drain on resources and can lead to developer burnout.

CVSS: Are Vulnerability Severity Scores Consistent?

The Common Vulnerability Scoring System (CVSS) is designed to provide a standardized way to assess the severity of vulnerabilities. However, Hovespyan and others argue that CVSS scores are often inconsistent and unreliable.

Inconsistent Scoring

One of the most significant criticisms of CVSS is the inconsistency of the scores. Hovespyan notes that studies have shown that more than 40% of CVEs receive different scores when re-evaluated by the same person just nine months later. This lack of consistency undermines the entire purpose of CVSS, making it difficult for organizations to prioritize vulnerabilities effectively.

Mathematical Misuse

Another issue is the way CVSS scores are used in calculations. CVSS scores are ordinal numbers, meaning they represent a position in a list rather than a quantitative value. However, they are often treated as quantitative values in security tool calculations and algorithms, which Hovespyan argues is mathematically unsound.

For example, you can’t simply average CVSS scores to get a meaningful overall risk score. It’s like averaging the finishing positions of runners in a race – it doesn’t tell you anything about their actual speed or performance.

Real-World Examples of CVSS Inconsistencies

Hovespyan cites several examples of problematic CVSS scores. One involves a CVE created by a PhD student for a deprecated system that no one was using. This vulnerability initially received a CVSS score of 9.1, indicating critical severity, before being downgraded.

Another example involves a curl vulnerability report that received a CVSS score of 9.8 out of 10, before being downgraded to 3.3. Daniel Stenberg, the creator and maintainer of curl, has been outspoken about the problems with CVSS, even writing a blog post titled “CVSS is dead to us.” Stenberg argues that a single score cannot accurately reflect the risk posed by a vulnerability in diverse environments.

Alternative Approaches to Vulnerability Management

While acknowledging that CVEs and CVSS scores still have some value as inputs, Hovespyan argues that they should not be the foundation of an entire application security strategy. He suggests a more holistic approach that focuses on threat modeling and contextual triage.

  • Threat Modeling: Identify potential threats and vulnerabilities based on the specific context of the application.
  • Contextual Triage: Prioritize vulnerabilities based on their potential impact on the organization, taking into account factors such as the sensitivity of the data, the likelihood of exploitation, and the availability of mitigations.

Daniel Stenberg’s perspective further reinforces this idea. He advocates for individual organizations to apply their own risk assessment and judgment on top of the base CVSS score. He also stated in an email interview, “This is one of the reasons why we in curl project actually don’t provide CVSS scores at all. We don’t think we can reliably set a single score for the world to (ab)use.”

The Limitations of Solely Relying on CVE/CVSS Data:

  • Ignores specific environment.
  • Often generates false positives.
  • Fails to consider unique attack vectors.

The shift from heavy reliance on CVEs and CVSS to threat modeling marks a step toward more accurate and relevant security approaches.

Conclusion: Moving Beyond CVE and CVSS Dependence

The current system of relying heavily on CVE and CVSS for vulnerability management is flawed. A significant portion of CVEs are unconfirmed or disputed, and CVSS scores are often inconsistent and unreliable. This can lead to wasted resources, misdirected security efforts, and ultimately, a false sense of security.

While CVEs and CVSS scores can still be valuable inputs, they should not be the sole basis for an organization’s application security strategy. Instead, organizations should adopt a more holistic approach that incorporates threat modeling and contextual triage, grounding security decisions in a deeper understanding of their specific risks.

What do you think? Are CVEs and CVSS scores still valuable, or are they contributing to a false sense of security? Comment below and share your thoughts!





Sources & Further Reading:
Original article at go.theregister.com

spot_imgspot_img

Subscribe

Related articles

Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison

Latvian national sentenced to 8.5 years for Karakurt ransomware negotiator role in $56M+ extortion scheme.

Google now offers up to $1.5 million for some Android exploits

Google overhauls Android and Chrome vulnerability rewards, offering up to $1.5 million for complex exploits while adjusting AI-discoverable flaw payouts.

Test Post Updated

This test post has been updated.

Weekly Deals: iPhone Air and iPhone 17 Price Cuts, Galaxy S26 and Pixel 10 Series on Sale

This Week's Best Smartphone DealsThe flagship smartphone market is...

Apple Unveils 2026 Pride Edition Sport Loop — A Rainbow Woven for Every Identity

A Band That Celebrates the Full SpectrumApple has launched...
spot_imgspot_img