CompTIA CySA+ (CS0-003)Vulnerability ManagementHard

A security analyst is reviewing a vulnerability report that lists a critical vulnerability (CVSS Base Score 9.8) in a web application. The vulnerability is a remote code execution flaw. However, the report indicates the CVSS Temporal Score is significantly lower. Upon investigation, the analyst discovers the following in the temporal vector string: `E:U/RL:O/RC:C`. What is the most likely reason for the lower temporal score?

  1. AThere is no publicly available exploit code for this vulnerability.
  2. BThe report includes false positive findings that skew the score.
  3. CA fix for the vulnerability is officially available from the vendor.
  4. DThe vulnerability is difficult to exploit and requires specialized knowledge.
Show answer & explanation

Correct answer: A. There is no publicly available exploit code for this vulnerability.

The CVSS Temporal Score is influenced by metrics like Exploit Code Maturity (E), Remediation Level (RL), and Report Confidence (RC). The 'E:U' in the vector string stands for 'Exploit Code Maturity: Unavailable', meaning there is no exploit code publicly available. This significantly lowers the temporal score compared to the base score, as the immediate threat of exploitation is reduced.

Why the other options are wrong

  • B. False positives affect the validity of findings, not directly the calculation of the temporal score metrics themselves.
  • C. RL:O (Remediation Level: Official Fix) would generally increase the temporal score's impact on reduction, as a fix is available, making it less urgent to exploit. However, E:U is the stronger factor here.
  • D. This relates to the Base Score metric 'Attack Complexity' (AC), not the temporal 'Exploit Code Maturity' (E'.

CVSS Temporal Metrics

Metrics that reflect the current state of exploit techniques or the availability of remediation and are subject to change over time.

  • Exploit Code Maturity (E): Availability of exploit code (U, P, F, H).
  • Remediation Level (RL): Availability of a fix (O, T, W, U, N).
  • Report Confidence (RC): Confidence in the existence of the vulnerability (U, R, C).

Memory trick: Temporal Score: Exploit, Remediation, Confidence – The 'ERC' of time-sensitive risk!

More Vulnerability Management questions