Rescore all vulnerabilities for a product version
As you know, the base CVSS score isn't tailored to your particular product's environment and usage. To ensure that you're spending your limited time resolving the vulnerabilities that matter most to your company, patient safety and your bottom line, you can create and apply rescore profiles to your various product versions.
Automatically update CVSS temporal metrics across product version
While applying a rescore profile to rescore all vulnerabilities across a product version, you can eliminate the need to manually track and update any exploitability changes, which are reflected in the CVSS v3 Temporal metrics. If there is any change to the metrics of Exploit Code Maturity, Remediation Level, and/or Report Confidence, your vulnerabilities will be automatically rescored based on this updated data.
After setting the Temporal and Environmental metrics that apply to particular product version, you can preview a sample of vulnerabilities to see how this will impact their scores, as well as how many vulnerabilities will be rescored. You can then apply it all vulnerabilities associated with this version.
Rescore all vulnerabilities in a product version
Streamline vulnerability management
Enabling this auto-update feature streamlines your vulnerability management processes, reduces manual effort, and ensures your CVSS severity scores are accurate and up-to-date:
Reduced effort: Save time and effort spent manually tracking and updating these metrics for each vulnerability.
Improved accuracy: Ensure that the CVSS Temporal metrics accurately reflect your vulnerabilities' current state, reducing the risk of human error during manual updates.
Simplified tracking: Eliminate the need to add information to the Evidence field for manual changes to these metrics.
Enable or disable automatic update of exploitability changes:
You can enable or disable the auto-updating of these Temporal exploitability metrics either while you're creating or editing a rescore profile. To do so:
Select the product and version, then click the Rescore drop-down button.
Choose the Edit rescore profile option. This will display the rescore panel.
In the Temporal section, toggle the Auto-update this vulnerability with exploitability changes switch. If you enable auto-update, the Temporal score metrics will become read-only, as they will be automatically updated based on exploitability changes. You can still individually rescore any vulnerability associated with this product, if desired. Note that the last change to a vulnerability, whether by a rescore profile or an individual rescore, will take precedence.
Click Save and apply changes.
Last updated