EH-Net

Resources => Tools => Topic started by: don on December 27, 2012, 12:00:45 PM



Title: Web Applications Vulnerabilities CVSSv2 Calculator
Post by: don on December 27, 2012, 12:00:45 PM
Thought this was a pretty interesting way to calculate risk. Although it is based on their own internal risk assessments, it might make for a good starting point in your own organization when talking to higher ups or generating a report to a client:

Quote

This calculator creates a CVSSv2 base score for vulnerabilities in web applications based on the High-Tech Bridge internal scoring system that is implemented in our HTB Security Advisories and is used to calculate risk of discovered vulnerabilities.

Not all vulnerabilities are scored in strict accordance to FIRST recommendations. Our CVSSv2 scores are based on our long internal experience in web applications auditing and penetration testing, taking into consideration a lot of practical nuances and details. Therefore sometimes they may differ from those ones that are recommended by FIRST.


Web Applications Vulnerabilities CVSSv2 Calculator:
https://www.htbridge.com/cvss_web_calculator/

Take a look and let us know what you think.

Don


Title: Re: Web Applications Vulnerabilities CVSSv2 Calculator
Post by: Grendel on December 27, 2012, 01:10:12 PM
That's actually pretty good - naturally, it needs to be modified based on the actual network architecture / security posture / etc... but that's probably why they say "we suggest."


Title: Re: Web Applications Vulnerabilities CVSSv2 Calculator
Post by: lorddicranius on December 27, 2012, 06:19:40 PM
That's handy!  Thanks for sharing, Don!