A security analyst is reviewing a vulnerability scan report for a critical production web server. The report indicates a Cross-Site Scripting (XSS) vulnerability with a CVSS Base Score of 7.2 (High). The analyst discovers that the server is protected by a Web Application Firewall (WAF) that is specifically configured to detect and block XSS attacks. How should this WAF deployment influence the final risk assessment and prioritization of this specific vulnerability?
- AThe WAF deployment has no impact on the base score; the vulnerability remains High.
- BThe WAF increases the attack complexity, thus lowering the CVSS Attack Vector.
- CThe WAF entirely eliminates the vulnerability, so it can be disregarded.
- DThe WAF acts as a compensating control, potentially lowering the effective risk and prioritization.
Show answer & explanationAnswer & explanation
Correct answer: D. The WAF acts as a compensating control, potentially lowering the effective risk and prioritization.
A WAF specifically configured to mitigate XSS acts as a compensating control. While it doesn't remove the underlying vulnerability in the application code (thus not changing the CVSS Base Score's exploitability or impact metrics directly), it significantly reduces the likelihood and/or impact of a successful exploitation, thereby lowering the effective risk and influencing prioritization.
Why the other options are wrong
- A. The base score is inherent to the vulnerability; compensating controls affect risk, not the base score itself.
- B. The WAF doesn't change the intrinsic Attack Vector of the vulnerability; it adds an external defense layer.
- C. The WAF doesn't eliminate the vulnerability from the application code; it only mitigates its exploitability at the perimeter.
Compensating Controls
Compensating controls are alternative security measures that are put in place to satisfy a security requirement when it is impractical or impossible to implement the primary control.
- They do not remove the underlying vulnerability but reduce the risk of its exploitation.
- Can influence the environmental or temporal CVSS scores, affecting prioritization.
- Often used for legacy systems or third-party applications where direct patching is not feasible.
Memory trick: Risk REDUCTION: Repair, Avoid, Accept, Transfer, Compensate.