RSA Security Advisories Severity Rating
Originally Published: 2009-07-08
Article Number
Applies To
Resolution
Severity Rating
A security vulnerability is classified by its severity rating, which is determined by many factors, including the level of effort required to exploit a vulnerability as well as the potential impact to data or business activities from a successful exploit. RSA currently uses the Common Vulnerability Scoring System version 3.0 (CVSS v3.0) to identify the severity level of identified vulnerabilities. The full standard, which is maintained by the Forum of Incident Response and Security Teams (FIRST), can be found at https://www.first.org/cvss.When and where applicable, RSA Security Advisories will provide the CVSS v3.0 Base Score, corresponding CVSS v3.0 Vector and the CVSS v3.0 Severity Rating Scale for identified vulnerabilities. RSA recommends that all customers take into account both the Base Score and any Temporal and/or Environmental Scores that may be relevant to their environment to assess their overall risk.
| CVSS v3 Base Score Metrics | Description | Possible Values | |
|---|---|---|---|
| Exploitability Metrics | Related exploit range | AttackVector (AV) | P = Physical access, L = Local access, A = Adjacent network, N = Network |
| Attack complexity | AttackComplexity (AC) | L = Low, H = High | |
| Level of privileges required | PrivilegesRequired(PR) | N = None required, L = Low privileges required, H = High privileges required | |
| User interaction | UserInteraction (UI) | N = None, R = Required | |
| Scope Metric | Scope | Scope (S) | U = Unchanged. No scope change, C = Changed. Scope changed |
| Impact Metrics | Confidentiality impact | ConfImpact (C) | N = None, L = Low, H = High |
| Integrity impact | IntegImpact (I) | N = None, L = Low, H = High | |
| Availability impact | AvailImpact (A) | N = None, L = Low, H = High | |
Severity
The Severity field in an RSA Security Advisory is defined with the value of Critical, High, Medium or Low based on the highest CVSSv3 score of the CVEs associated with the advisory. The severity level is determined based on the criteria below.| Severity Level | Criteria |
|---|---|
| Critical | CVSSv3 base score is greater than or equal to 9.0 |
| High | CVSSv3 base score is greater than or equal to 7.0 but less than 9.0 |
| Medium | CVSSv3 base score is greater than or equal to 4.0 but less than 7.0 |
| Low | CVSSv3 base score is less than or equal to 3.9 |
Related Articles
Reporting Engine service is not running due to reportstatusmanager.h2.db corrupt 14Number of Views RSA Announces Critical Security Updates for RSA ID Plus Components - RSA Authentication Manager and RSA Identity Router 858Number of Views RSA MFA Agent for Windows will not run due to error "This module is blocked from loading into the Local Security Authority" 850Number of Views How to Check Local File System Disk Space in RSA Governance & Lifecycle 1.39KNumber of Views RSA SecurID Hardware Appliance Component Updates 505Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager Upgrade Process Running out of disk space when using RMAN in RSA Identity Governance & Lifecycle
Don't see what you're looking for?