How does the Juniper Networks Security Incident Response Team (Juniper SIRT) use the Common Vulnerability Scoring System (CVSS)?
The Common Vulnerability Scoring System (CVSS) provides a way to capture the principal technical characteristics of software, hardware and firmware vulnerabilities, and produce numerical scores indicating the severity of a vulnerability relative to other vulnerabilities. The numerical score can then be mapped to a Qualitative Severity Rating (Low, Medium, High, Critical) to help organizations properly assess and prioritize vulnerabilities within their vulnerability management system.CVSS provides standardized vulnerability scores. When an organization uses a common algorithm for scoring vulnerabilities across all IT, OT, and ICS platforms, it can leverage a single vulnerability management policy defining the maximum allowable time to validate and remediate a given vulnerability. As an open standard, the individual characteristics used to derive a CVSS score are based on standardized metrics and metric values that are clearly documented and transparent.Juniper Networks uses CVSS for all reported vulnerabilities. The CVSS Base Score (CVSS-B) is used as a starting point to gauge the severity of a vulnerability and set priorities for the fix and remediation. Customers can use the CVSS Base Score, optionally enhanced by providing CVSS Threat and Environmental metrics, to perform a full CVSS assessment (see the CVSS Guide below). The complete CVSS Score (CVSS-BTE) will provide customers with a more precise understanding of the vulnerability's severity as it relates to their specific environment, using available threat intelligence.In November 2023, the CVSS Special Interest Group (SIG), of which Juniper Networks is an active participant, published version 4.0 of the CVSS specification. CVSS v4.0 is quickly gaining worldwide adoption, and beginning in January 2024, the Juniper SIRT is publishing both CVSS v3.1 and v4.0 Base Scores for all Juniper Security Advisories going forward. Refer to What's New in CVSS v4.0, the CVSS v4.0 Specification Document, User Guide, FAQ, and Examples for more information about the improvements to the CVSS specification found in version 4.0. Online self-paced training is also available.
2010-01-05: Initial publication 2019-07-09: Updated references to CVSS v3.1 2024-01-08: Updated references to CVSS v4.0