Any further references to this? I’d love to have something I can send around internally. The people running Tenable tend to treat these numbers as gospel.
We also do this with pen test reports which suffer the same kinds of issues.
Usually find that sometimes a medium is a critical for us and some times a high is a low for us - based on performing this kind of assessment.
Totally agree, and I do that - check the vulnerability description, see if we’re using that part of the library, etc… it usually works out that we’re not actually affected by whatever the alert is.
If you don't see dysfunction, you're not looking closely enough. That's not to say all organizations are equivalently dysfunctional or that we shouldn't strive for better. I'm just saying that "dysfunctional" isn't a damning accusation.
I like the scores - just ask them - what's the score.
CVSS is generally used on the sysadmin side to figure out what to patch first. Successful attackers generally go after shit that's unpatched. This often means that the most exploited bugs are the ones with the lowest CVSS scores, so new tools and techniques tend to grow around issues that sysadmins consider to not be a big deal.
People eventually catch on that the "no big deal" bugs are getting exploited en-masse, and try to tweak the scoring process, which is why we're on CVSSv3 now with CVSSv4 in the works, and it's just as useless as it's always been.
Namely, you should be taking the base CVSS score and including the temporal and environment metrics to actually determine your organizational risk. A base 9.x could easily be driven to low based on the access, exploitability, and CIA requirements for the system at hand.
So its a serious vuln, but not as serious as say if it was in a component that was always exposed to the internet in the core part of vmware. I guess vulns can always be worse.
How bad it is depends on how you use vmware. I mean regardless, clearly everyone affected should patch.