Will Putting a Dollar Value on Vulnerabilities Help Prioritize Them?

December 18, 2023 at 03:42PM Zoom developed the Vulnerability Impact Scoring System (VISS) as a more objective approach to assess the severity of vulnerabilities found during bug bounty programs. This system, providing a transparent and defensible way to calculate potential rewards for vulnerabilities, aims to prioritize critical and high-severity issues. VISS received positive feedback from … Read more

Zoom Unveils Open Source Vulnerability Impact Scoring System

December 15, 2023 at 08:36AM Zoom unveiled an open source Vulnerability Impact Scoring System (VISS) to help organizations assess and prioritize vulnerabilities based on actual exploitation. The system, designed to complement the Common Vulnerability Scoring System, led to increased reports of critical vulnerabilities during testing and analyzes vulnerabilities based on 13 impact aspects. It remains … Read more

Zoom’s Bug-Scoring System Prioritizes Riskiest Vulns for Cyber Teams

December 14, 2023 at 09:03AM Zoom has introduced a new Vulnerability Impact Scoring System (VISS) to help cybersecurity teams prioritize threats. It analyzes 13 impact aspects, produces a 0-100 score, and can be adjusted using compensating controls. In testing, critical vulnerabilities increased by 28%, while medium-severity ones decreased by 57%. Zoom aims to enhance security … Read more

New CVSS 4.0 vulnerability severity rating standard released

November 1, 2023 at 03:32PM FIRST has released CVSS v4.0, the latest version of its Common Vulnerability Scoring System standard after eight years. CVSS provides a framework for assessing the severity of software security vulnerabilities, helping prioritize responses to security threats. The new version offers finer granularity, removes scoring ambiguity, simplifies metrics, and adds supplemental … Read more