Hello Hartmut,

Thanks for raising this issue, kind of gave us a push to take some action.

Yes, they are not being regularly updated once the vulnerability status
changes. One option is of course to maintain that regulalry and the other
option is to not have Temporal Score and give the user flexibility to
calculate temporal score on their own, only include "Base Score".

I think, am inclined to not have temporal score, in which case we'll update
all scripts to not have that. Any suggestion from anyone?

Thanks
Chandra.

> -----Original Message-----
> From: [email protected] [mailto:openvas-discuss-
> [email protected]] On Behalf Of Hartmut Goebel
> Sent: Tuesday, April 27, 2010 4:32 PM
> To: [email protected]
> Subject: [Openvas-discuss] How is maintaining the CVSS temporal scores?
> 
> Hi,
> 
> as I just discovered, about 1400 NVT scripts contain a "CVSS temporal"
> score, about 250 of them tag the script  with this score.
> 
> I wonder who is maintaining this information. CVSS temporal scores are
> meant to change over time. If nobody is in charge of doing this, it is
> plain worthless -- even more: counterproductive -- to have it in the
> scripts.
> 
> --
> Schönen Gruß - Regards
> Hartmut Goebel
> Dipl.-Informatiker (univ.), CISSP, CSSLP
> 
> Goebel Consult
> Spezialist für IT-Sicherheit in komplexen Umgebungen
> http://www.goebel-consult.de
> 
> Monatliche Kolumne: http://www.cissp-gefluester.de/
> Goebel Consult mit Mitglied bei http://www.7-it.de


_______________________________________________
Openvas-discuss mailing list
[email protected]
http://lists.wald.intevation.org/mailman/listinfo/openvas-discuss

Reply via email to