Hello Hartmut, Thanks for raising this issue, kind of gave us a push to take some action.
Yes, they are not being regularly updated once the vulnerability status changes. One option is of course to maintain that regulalry and the other option is to not have Temporal Score and give the user flexibility to calculate temporal score on their own, only include "Base Score". I think, am inclined to not have temporal score, in which case we'll update all scripts to not have that. Any suggestion from anyone? Thanks Chandra. > -----Original Message----- > From: [email protected] [mailto:openvas-discuss- > [email protected]] On Behalf Of Hartmut Goebel > Sent: Tuesday, April 27, 2010 4:32 PM > To: [email protected] > Subject: [Openvas-discuss] How is maintaining the CVSS temporal scores? > > Hi, > > as I just discovered, about 1400 NVT scripts contain a "CVSS temporal" > score, about 250 of them tag the script with this score. > > I wonder who is maintaining this information. CVSS temporal scores are > meant to change over time. If nobody is in charge of doing this, it is > plain worthless -- even more: counterproductive -- to have it in the > scripts. > > -- > Schönen Gruß - Regards > Hartmut Goebel > Dipl.-Informatiker (univ.), CISSP, CSSLP > > Goebel Consult > Spezialist für IT-Sicherheit in komplexen Umgebungen > http://www.goebel-consult.de > > Monatliche Kolumne: http://www.cissp-gefluester.de/ > Goebel Consult mit Mitglied bei http://www.7-it.de _______________________________________________ Openvas-discuss mailing list [email protected] http://lists.wald.intevation.org/mailman/listinfo/openvas-discuss
