Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You're conflating two systems here: CVSS' ratings and CVE's vulnerability IDing

Something receiving 9.8 when you feel like it should be a 4–5 is a common enough complaint, though typically not this extreme. If the parameters are filled in correctly (you didn't mention even checking why the result was 9.8) then that's not a flaw in the CVE system.

Conversely, CVE authorities not responding to requests for deletion aren't the same as using an inaccurate impact/exploitability calculation system called CVSS



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: