RSA Security Advisories Severity Rating
Originally Published: 2009-07-08
Last Modified: 2026-04-30
Article Number
Applies To
Resolution
Severity Rating
A security vulnerability is classified by its severity rating, which is determined by many factors, including the level of effort required to exploit a vulnerability as well as the potential impact to data or business activities from a successful exploit. RSA currently uses the Common Vulnerability Scoring System version 3.0 (CVSS v3.0) to identify the severity level of identified vulnerabilities. The full standard, which is maintained by the Forum of Incident Response and Security Teams (FIRST), can be found at https://www.first.org/cvss.When and where applicable, RSA Security Advisories will provide the CVSS v3.0 Base Score, corresponding CVSS v3.0 Vector and the CVSS v3.0 Severity Rating Scale for identified vulnerabilities. RSA recommends that all customers take into account both the Base Score and any Temporal and/or Environmental Scores that may be relevant to their environment to assess their overall risk.
| CVSS v3 Base Score Metrics | Description | Possible Values | |
|---|---|---|---|
| Exploitability Metrics | Related exploit range | AttackVector (AV) | P = Physical access, L = Local access, A = Adjacent network, N = Network |
| Attack complexity | AttackComplexity (AC) | L = Low, H = High | |
| Level of privileges required | PrivilegesRequired(PR) | N = None required, L = Low privileges required, H = High privileges required | |
| User interaction | UserInteraction (UI) | N = None, R = Required | |
| Scope Metric | Scope | Scope (S) | U = Unchanged. No scope change, C = Changed. Scope changed |
| Impact Metrics | Confidentiality impact | ConfImpact (C) | N = None, L = Low, H = High |
| Integrity impact | IntegImpact (I) | N = None, L = Low, H = High | |
| Availability impact | AvailImpact (A) | N = None, L = Low, H = High | |
Severity
The Severity field in an RSA Security Advisory is defined with the value of Critical, High, Medium or Low based on the highest CVSSv3 score of the CVEs associated with the advisory. The severity level is determined based on the criteria below.| Severity Level | Criteria |
|---|---|
| Critical | CVSSv3 base score is greater than or equal to 9.0 |
| High | CVSSv3 base score is greater than or equal to 7.0 but less than 9.0 |
| Medium | CVSSv3 base score is greater than or equal to 4.0 but less than 7.0 |
| Low | CVSSv3 base score is less than or equal to 3.9 |
Related Articles
How to correctly utilize the RSASecurIDAuthenticationEngine.resynch method 35Number of Views Authentication Manager Bulk Admin (AMBA) script fails to run with “Invalid header field name” error 100Number of Views Disaster Recovery Situations 50Number of Views What are the token windows used for Event-based tokens? 52Number of Views RSA Customer Advisory: ClamAV Vulnerability CVE-2023-20032 CVE-2023-20052 95Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?