1. CVSS v4.0 — Tổng quan
CVSS v4.0 (Common Vulnerability Scoring System):
Released: November 2023 by FIRST.org
Major update from v3.1
Key Changes v3.1 → v4.0:
├── New metric groups (Supplemental)
├── Granular Impact metrics (VC, VI, VA, SC, SI, SA)
├── Attack Requirements (AT) — new metric
├── Removed Scope — replaced by dual impact
├── Renamed Temporal → Threat
├── New Supplemental metrics (Safety, Recovery, etc.)
└── More precise scoring formula
CVSS v4.0 Metric Groups:
┌─────────────────────────────────────────────┐
│ Base Metrics (required) │
│ ├── Exploitability: AV, AC, AT, PR, UI │
│ └── Impact: VC, VI, VA, SC, SI, SA │
├─────────────────────────────────────────────┤
│ Threat Metrics (optional) │
│ └── Exploit Maturity (E) │
├─────────────────────────────────────────────┤
│ Environmental Metrics (optional) │
│ ├── Modified Base Metrics │
│ └── Security Requirements (CR, IR, AR) │
├─────────────────────────────────────────────┤
│ Supplemental Metrics (optional, informational)│
│ ├── Safety (S), Automatable (AU) │
│ ├── Recovery (R), Value Density (V) │
│ ├── Vulnerability Response Effort (RE) │
│ └── Provider Urgency (U) │
└─────────────────────────────────────────────┘
2. Base Metrics — Exploitability
Exploitability Metrics:
Attack Vector (AV):
├── Network (N) : Remotely exploitable (internet)
├── Adjacent (A) : Same network segment
├── Local (L) : Local access required
└── Physical (P) : Physical access to device
Attack Complexity (AC):
├── Low (L) : No special conditions needed
└── High (H) : Specific conditions required
Attack Requirements (AT): ← NEW in v4.0
├── None (N) : No prerequisites
└── Present (P): Specific deployment/config needed
Privileges Required (PR):
├── None (N) : No authentication needed
├── Low (L) : Basic user privileges
└── High (H) : Admin/elevated privileges
User Interaction (UI):
├── None (N) : No user action needed
├── Passive (P): Minimal interaction (visit page) ← NEW
└── Active (A) : User must perform specific action ← NEW
Example Mapping:
SQL Injection (unauthenticated):
AV:N / AC:L / AT:N / PR:N / UI:N
Stored XSS (authenticated):
AV:N / AC:L / AT:N / PR:L / UI:P
Local privilege escalation:
AV:L / AC:L / AT:N / PR:L / UI:N
3. Base Metrics — Impact
Impact Metrics (v4.0 Dual System):
Vulnerable System Impact: Subsequent System Impact:
VC: Confidentiality SC: Confidentiality
VI: Integrity SI: Integrity
VA: Availability SA: Availability
Each rated: None (N) / Low (L) / High (H)
"Vulnerable System" = the system with the vulnerability
"Subsequent System" = other systems affected (replaces Scope)
Examples:
1. SQL Injection → Database dump:
VC:H (all data exposed) SC:N (contained to DB)
VI:H (can modify data) SI:N
VA:H (can DROP tables) SA:N
2. SSRF → AWS Metadata → Full AWS account:
VC:L (limited initial data) SC:H (AWS credentials → all data)
VI:N SI:H (can modify AWS resources)
VA:N SA:H (can terminate instances)
3. Stored XSS → Session hijacking:
VC:L (session token) SC:L (victim's session)
VI:L (page modification) SI:L (actions as victim)
VA:N SA:N
4. Threat & Environmental Metrics
Threat Metrics:
Exploit Maturity (E):
├── Not Defined (X): Default, no info
├── Attacked (A) : Active exploitation in the wild
├── POC (P) : Proof-of-concept exists
└── Unreported (U) : No known exploit
Effect on score:
E:A → Score stays same or increases
E:U → Score decreases (lower real-world risk)
Environmental Metrics:
Modified Base Metrics:
Override any base metric based on your environment
Example: If you have WAF → MAV might be lower
Security Requirements (CR, IR, AR):
├── Not Defined (X)
├── High (H) : System is mission-critical
├── Medium (M) : Standard importance
└── Low (L) : Non-critical system
Example:
Base: CVSS 8.1 (High)
Environment: Non-production test server
Modified: CR:L, IR:L, AR:L
Environmental Score: ~5.5 (Medium) — lower priority
5. Thực hành Scoring
Scenario 1: Unauthenticated SQL Injection in Payment API
Base Metrics:
AV:N — Network accessible
AC:L — No special conditions
AT:N — No prerequisites
PR:N — No auth required
UI:N — No user interaction
VC:H — Full database access
VI:H — Can modify data
VA:H — Can disrupt service
SC:N — Contained to this system
SI:N
SA:N
CVSS-B: 9.3 (Critical)
Threat: E:A (actively exploited)
CVSS-BT: 9.3
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A
---
Scenario 2: IDOR — Access other users' profile photos
Base Metrics:
AV:N — Network accessible
AC:L — No special conditions
AT:N — No prerequisites
PR:L — Need authenticated account
UI:N — No user interaction
VC:L — Limited data (photos only)
VI:N — Can't modify
VA:N — No availability impact
SC:N — No subsequent system impact
SI:N
SA:N
CVSS-B: 4.3 (Medium)
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
---
Scenario 3: SSRF → AWS Metadata → Account Takeover
Base Metrics:
AV:N — Network accessible
AC:L — No special conditions
AT:P — Requires IMDSv1 to be enabled
PR:N — No auth required
UI:N — No user interaction
VC:N — No direct vuln system data
VI:N
VA:N
SC:H — Full AWS credential access
SI:H — Can modify all AWS resources
SA:H — Can terminate instances
CVSS-B: 9.3 (Critical)
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
6. So sánh CVSS v3.1 vs v4.0
| Aspect | CVSS v3.1 | CVSS v4.0 |
|---|---|---|
| Scope | Changed/Unchanged | Removed → dual impact |
| User Interaction | None/Required | None/Passive/Active |
| Temporal | 3 metrics | 1 metric (Exploit Maturity) |
| Attack Requirements | N/A | None/Present (new) |
| Impact | C/I/A (single) | VC/VI/VA + SC/SI/SA (dual) |
| Supplemental | N/A | Safety, Recovery, etc. |
| Naming | CVSS-B, CVSS-T, CVSS-E | CVSS-B, CVSS-BT, CVSS-BE, CVSS-BTE |
| Score range | 0.0 - 10.0 | 0.0 - 10.0 |
7. Tổng kết
- CVSS v4.0: More granular than v3.1 — dual impact, attack requirements
- Base: AV/AC/AT/PR/UI + VC/VI/VA/SC/SI/SA
- Threat: Exploit Maturity — adjust for real-world risk
- Environmental: Customize for your infrastructure
- Practice: Use FIRST CVSS Calculator for accurate scoring
Bài tiếp theo sẽ hướng dẫn viết Performance Test Report chuyên nghiệp.