Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add CVSSv4 crosswalk #6

Open
ahouseholder opened this issue Sep 27, 2023 · 1 comment
Open

Add CVSSv4 crosswalk #6

ahouseholder opened this issue Sep 27, 2023 · 1 comment
Milestone

Comments

@ahouseholder
Copy link
Contributor

Some elements of CVSSv4 vectors have implications for interaction with Vultron states. We should map those out as a crosswalk similar to https://certcc.github.io/Vultron/reference/ssvc_crosswalk

@ahouseholder
Copy link
Contributor Author

Following is what we had said about CVSS 3.1 in the State-based model paper

CVSS version 3.1
includes a few Temporal Metric variables that connect to this model.
Unfortunately, differences in abstraction between the models leaves a good
deal of ambiguity in the translation. The table below shows the
relationship between the two models.

States CVSS v3.1 Temporal Metric CVSS v3.1 Temporal Metric Value(s)
$\cdot\cdot\cdot\cdot XA$ Exploit Maturity High (H), or Functional (F)
$\cdot\cdot\cdot\cdot X \cdot$ Exploit Maturity High (H), Functional (F), or Proof-of-Concept (P)
$\cdot\cdot\cdot\cdot x \cdot$ Exploit Maturity Unproven (U) or Not Defined (X)
$Vf\cdot\cdot\cdot\cdot$ Remediation Level Not Defined (X), Unavailable (U), Workaround (W), or Temporary Fix (T)
$VF\cdot\cdot\cdot\cdot$ Remediation Level Temporary Fix (T) or Official Fix (O)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant