Bobby Liu.
← Security notebook

Reference note

CVE / CVSS

How vulnerabilities are identified, scored, prioritized, remediated, and verified.

The vulnerability workflow

  • Discover — identify assets and maintain an inventory.
  • Prioritize assets — categorize systems by importance and address high-impact systems first.
  • Assess — scan and check systems continuously for vulnerabilities.
  • Report — tailor findings to the needs of each intended audience.
  • Remediate — build a prioritized plan, fix vulnerable systems, and document each step.
  • Verify — perform follow-up scans to confirm that vulnerabilities and threats were addressed.

CVE — Common Vulnerabilities and Exposures

CVE identifiers give publicly known vulnerabilities a standard name. This shared naming system makes it easier for tools, vendors, researchers, and organizations to exchange information about the same security issue. The CVE program is operated by MITRE and assigns each published vulnerability a unique identifier.

CVSS — Common Vulnerability Scoring System

CVSS measures the characteristics and potential impact of a vulnerability. A base score from 0.0 to 10.0 maps to a severity rating from None through Critical, helping teams compare findings and decide which work should be prioritized. Organizations can use the NVD calculator when they need to calculate or adjust a score.

Visual reference

Click an image to expand
Vulnerability management life cycle
Vulnerability life cycle summary
Common Vulnerabilities and Exposures
CVSS severity ratings and base scores