Beers with Talos Podcast

Should we even care about vulnerability severity scores?

March 16, 2023 Cisco Talos Episode 131
Beers with Talos Podcast
Should we even care about vulnerability severity scores?
Show Notes

Everyone fears the dreaded 10-out-of-10 CVSS severity score on a vulnerability with "critical" written somewhere on the advisory. But does that number even matter to an attacker or hypothetical defender? Matt, Mitch and Lurene discuss the various ways the security community classifies vulnerabilities and how potential targets can use that information to their advantage. They discuss patching strategies, potential security holes that attackers look for and real-world cases of vulnerabilities that have led to breaches or cyber attacks.

Other suggested talking points:

  • Band jam sessions
  • Conference season getting underway
  • Whether Tom Petty's music is actually complex