cvss-v31-specification_r1原文信息安全资料 .docxVIP

  • 0
  • 0
  • 约5.4万字
  • 约 24页
  • 2026-02-10 发布于浙江
  • 举报

cvss-v31-specification_r1原文信息安全资料 .docx

TLP:WHITE

CommonVulnerabilityScoringSystemversion3.1

SpecificationDocument

Revision1

TheCommonVulnerabilityScoringSystem(CVSS)isanopenframeworkforcommunicatingthecharacteristicsandseverityofsoftwarevulnerabilities.CVSSconsistsofthreemetricgroups:Base,Temporal,andEnvironmental.TheBasegrouprepresentstheintrinsicqualitiesofavulnerabilitythatareconstantovertimeandacrossuserenvironments,theTemporalgroupreflectsthecharacteristicsofavulnerabilitythatchangeovertime,andtheEnvironmentalgrouprepresentsthecharacteristicsofavulnerabilitythatareuniquetoausersenvironment.TheBasemetricsproduceascorerangingfrom0to10,whichcanthenbemodifiedbyscoringtheTemporalandEnvironmentalmetrics.ACVSSscoreisalsorepresentedasavectorstring,acompressedtextualrepresentationofthevaluesusedtoderivethescore.ThisdocumentprovidestheofficialspecificationforCVSSversion3.1.

ThemostcurrentCVSSresourcescanbefoundat/cvss/

CVSSisownedandmanagedbyFIRST.Org,Inc.(FIRST),aUS-basednon-profitorganization,whosemissionistohelpcomputersecurityincidentresponseteamsacrosstheworld.FIRSTreservestherighttoupdateCVSSandthisdocumentperiodicallyatitssolediscretion.WhileFIRSTownsallrightandinterestinCVSS,itlicensesittothepublicfreelyforuse,subjecttotheconditionsbelow.MembershipinFIRSTisnotrequiredtouseorimplementCVSS.FIRSTdoes,however,requirethatanyindividualorentityusingCVSSgiveproperattribution,whereapplicable,thatCVSSisownedbyFIRSTandusedbypermission.Further,FIRSTrequiresasaconditionofusethatanyindividualorentitywhichpublishesscoresconformstotheguidelinesdescribedinthisdocumentandprovidesboththescoreandthescoringvectorsootherscanunderstandhowthescorewasderived.

Contents

1.Introduction3

TLP:WHITE

TLP:WHITE

1.1.Metrics31.2.Scoring52.Base

文档评论(0)

1亿VIP精品文档

相关文档