Chuyển đến nội dung chính

Bài 26: CVSS v4.0 Scoring

CVSS v4.0 metrics, Base/Threat/Environmental scoring, so sánh với v3.1, thực hành tính severity.

🔒 DevSecOps — Bài 26 Bài 26: CVSS v4.0 Scoring

Performance Testing & Pentest: Quy trình Chuẩn Doanh nghiệp 2026

Phần 6: Báo cáo & Quy trình Chuyên nghiệp

xdev.asia

1. CVSS v4.0 — Tổng quan

CVSS v4.0 (Common Vulnerability Scoring System):
Released: November 2023 by FIRST.org
Major update from v3.1

Key Changes v3.1 → v4.0:
  ├── New metric groups (Supplemental)
  ├── Granular Impact metrics (VC, VI, VA, SC, SI, SA)
  ├── Attack Requirements (AT) — new metric
  ├── Removed Scope — replaced by dual impact
  ├── Renamed Temporal → Threat
  ├── New Supplemental metrics (Safety, Recovery, etc.)
  └── More precise scoring formula

CVSS v4.0 Metric Groups:

┌─────────────────────────────────────────────┐
│  Base Metrics (required)                     │
│  ├── Exploitability: AV, AC, AT, PR, UI     │
│  └── Impact: VC, VI, VA, SC, SI, SA         │
├─────────────────────────────────────────────┤
│  Threat Metrics (optional)                   │
│  └── Exploit Maturity (E)                    │
├─────────────────────────────────────────────┤
│  Environmental Metrics (optional)            │
│  ├── Modified Base Metrics                   │
│  └── Security Requirements (CR, IR, AR)      │
├─────────────────────────────────────────────┤
│  Supplemental Metrics (optional, informational)│
│  ├── Safety (S), Automatable (AU)            │
│  ├── Recovery (R), Value Density (V)         │
│  ├── Vulnerability Response Effort (RE)      │
│  └── Provider Urgency (U)                    │
└─────────────────────────────────────────────┘

2. Base Metrics — Exploitability

Exploitability Metrics:

Attack Vector (AV):
  ├── Network (N)   : Remotely exploitable (internet)
  ├── Adjacent (A)  : Same network segment
  ├── Local (L)     : Local access required
  └── Physical (P)  : Physical access to device

Attack Complexity (AC):
  ├── Low (L)    : No special conditions needed
  └── High (H)   : Specific conditions required

Attack Requirements (AT):  ← NEW in v4.0
  ├── None (N)   : No prerequisites
  └── Present (P): Specific deployment/config needed

Privileges Required (PR):
  ├── None (N)   : No authentication needed
  ├── Low (L)    : Basic user privileges
  └── High (H)   : Admin/elevated privileges

User Interaction (UI):
  ├── None (N)   : No user action needed
  ├── Passive (P): Minimal interaction (visit page)  ← NEW
  └── Active (A) : User must perform specific action  ← NEW

Example Mapping:
  SQL Injection (unauthenticated):
    AV:N / AC:L / AT:N / PR:N / UI:N

  Stored XSS (authenticated):
    AV:N / AC:L / AT:N / PR:L / UI:P

  Local privilege escalation:
    AV:L / AC:L / AT:N / PR:L / UI:N

3. Base Metrics — Impact

Impact Metrics (v4.0 Dual System):

Vulnerable System Impact:    Subsequent System Impact:
  VC: Confidentiality          SC: Confidentiality
  VI: Integrity                SI: Integrity
  VA: Availability             SA: Availability

Each rated: None (N) / Low (L) / High (H)

"Vulnerable System" = the system with the vulnerability
"Subsequent System" = other systems affected (replaces Scope)

Examples:

1. SQL Injection → Database dump:
   VC:H (all data exposed)  SC:N (contained to DB)
   VI:H (can modify data)   SI:N
   VA:H (can DROP tables)   SA:N

2. SSRF → AWS Metadata → Full AWS account:
   VC:L (limited initial data)  SC:H (AWS credentials → all data)
   VI:N                         SI:H (can modify AWS resources)
   VA:N                         SA:H (can terminate instances)

3. Stored XSS → Session hijacking:
   VC:L (session token)     SC:L (victim's session)
   VI:L (page modification) SI:L (actions as victim)
   VA:N                     SA:N

4. Threat & Environmental Metrics

Threat Metrics:

Exploit Maturity (E):
  ├── Not Defined (X): Default, no info
  ├── Attacked (A)   : Active exploitation in the wild
  ├── POC (P)        : Proof-of-concept exists
  └── Unreported (U) : No known exploit

Effect on score:
  E:A → Score stays same or increases
  E:U → Score decreases (lower real-world risk)

Environmental Metrics:

Modified Base Metrics:
  Override any base metric based on your environment
  Example: If you have WAF → MAV might be lower

Security Requirements (CR, IR, AR):
  ├── Not Defined (X)
  ├── High (H)  : System is mission-critical
  ├── Medium (M) : Standard importance
  └── Low (L)   : Non-critical system

Example:
  Base: CVSS 8.1 (High)
  Environment: Non-production test server
  Modified: CR:L, IR:L, AR:L
  Environmental Score: ~5.5 (Medium) — lower priority

5. Thực hành Scoring

Scenario 1: Unauthenticated SQL Injection in Payment API

  Base Metrics:
    AV:N   — Network accessible
    AC:L   — No special conditions
    AT:N   — No prerequisites
    PR:N   — No auth required
    UI:N   — No user interaction
    VC:H   — Full database access
    VI:H   — Can modify data
    VA:H   — Can disrupt service
    SC:N   — Contained to this system
    SI:N
    SA:N

  CVSS-B: 9.3 (Critical)

  Threat: E:A (actively exploited)
  CVSS-BT: 9.3

  Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A

---

Scenario 2: IDOR — Access other users' profile photos

  Base Metrics:
    AV:N   — Network accessible
    AC:L   — No special conditions
    AT:N   — No prerequisites
    PR:L   — Need authenticated account
    UI:N   — No user interaction
    VC:L   — Limited data (photos only)
    VI:N   — Can't modify
    VA:N   — No availability impact
    SC:N   — No subsequent system impact
    SI:N
    SA:N

  CVSS-B: 4.3 (Medium)

  Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

---

Scenario 3: SSRF → AWS Metadata → Account Takeover

  Base Metrics:
    AV:N   — Network accessible
    AC:L   — No special conditions
    AT:P   — Requires IMDSv1 to be enabled
    PR:N   — No auth required
    UI:N   — No user interaction
    VC:N   — No direct vuln system data
    VI:N
    VA:N
    SC:H   — Full AWS credential access
    SI:H   — Can modify all AWS resources
    SA:H   — Can terminate instances

  CVSS-B: 9.3 (Critical)

  Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H

6. So sánh CVSS v3.1 vs v4.0

AspectCVSS v3.1CVSS v4.0
ScopeChanged/UnchangedRemoved → dual impact
User InteractionNone/RequiredNone/Passive/Active
Temporal3 metrics1 metric (Exploit Maturity)
Attack RequirementsN/ANone/Present (new)
ImpactC/I/A (single)VC/VI/VA + SC/SI/SA (dual)
SupplementalN/ASafety, Recovery, etc.
NamingCVSS-B, CVSS-T, CVSS-ECVSS-B, CVSS-BT, CVSS-BE, CVSS-BTE
Score range0.0 - 10.00.0 - 10.0

7. Tổng kết

  • CVSS v4.0: More granular than v3.1 — dual impact, attack requirements
  • Base: AV/AC/AT/PR/UI + VC/VI/VA/SC/SI/SA
  • Threat: Exploit Maturity — adjust for real-world risk
  • Environmental: Customize for your infrastructure
  • Practice: Use FIRST CVSS Calculator for accurate scoring

Bài tiếp theo sẽ hướng dẫn viết Performance Test Report chuyên nghiệp.