Forum Discussion
CvssScore in "DeviceTvmSoftwareVulnerabilitiesKB" - What is it and is it accurate?
- Joseph770Dec 19, 2023Copper Contributor
"You don't mention which version is being used in the comparison."
The NVD reference given uses CVSS 3.x. What Microsoft is using is my concern as they are way out of alignment with the NVD listing. The lack of definition provided by Microsoft for the CvssScore combined with a value, probably meant to be the base score, that is so different raises concerns for the validity of the data Microsoft is managing (or not).- ExMSW4319Dec 19, 2023Iron ContributorThere is a click button on the NVD web site that in theory will show the CVSS v2 score. It is not obvious. However, for CVE-2023-27350 you are right; they have only calculated / published a score for v3.
- Joseph770Dec 19, 2023Copper Contributor
I spent some time over lunch comparing the CVSS scores for the 2023 entries (those entries starting with "CVE-2023-") in the NVD database to those in the DeviceTvmSoftwareVulnerabilitiesKB table. Where there was a matching CVE in both, more than 33% of the CvssScore in the DeviceTvmSoftwareVulneratiliesKB table did not match the CVSS base score in the NVD. Maybe "Defender XDR" will get rebranded "Defender RND"?
- ExMSW4319Dec 19, 2023Iron ContributorAnd I have muddled my temporal and base scores. For CVE-2023-27350 the correct scores are v2 base 10 temporal 8.3 and v3 base 9.8 temporal 9.1. Lots to choose from.