Unless there’s a minimum standard it becomes noise, and the real CVEs are lost.
Unless there’s a minimum standard it becomes noise, and the real CVEs are lost.
Trying to ignore the extreme hyperbole here...
I want me or my team to see every security-related flaw affecting the products in our network, yes. That's literally our job.
A CVE like this takes maybe 2 minutes for a junior on the team to mark as no risk.
Because the people that do conduct sophisticated attacks are studying every knock and cranny for these types of things. If they can find it once, they can automate it and find more. And then they move on to the next piece of their puzzle of "what can I do from here?"
A lot of this can/should be boiled down to: are our updates and mirrors current?
One selects an OS vendor/distribution explicitly to make this kind of thing their ~problem~ responsibility. They gave me "foo", they can fix it.
There's usually no problem because nobody builds everything from upstream sources. The security vendor yells at me and the OS vendor about discoveries in something they never packaged.
Each distribution gets sufficiently involved that I refuse to mind most CVEs. Eternally grateful my current role allows me to drop this charade
My CVSS score for this is as follows:
CVSSv3.1:AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L (I said "Low" integrity issues, and "Low" availability issues, since I don't know if the DOS issue is real)
That reads out to a "Medium" CVE.
I have, in the past, worked with some banks, and they want all 4+ CVSSv3 CVEs enumerated and either remediated or for a plan to be in place to remediate them.
Maybe you're significantly better than I am at this, but I am hesitant to look at any CVE and say it's not a problem with how I have configured my software. Unless I have really deeply looked into the issue, I get really nervous saying a CVE is not going to affect my software.
If you want to dedicate staff to reviewing useless garbage issues you do that, go and review every issue logged against other non-commercial software.
The rest of us have a job to do.
I'm not sure why you are being hostile about it, but okay.
Obviously you feel very strongly about the subject. You should engage with MITRE and encourage them to reconsider their current CVE inclusion decision tree.
I also wonder how the attacker got access to Bob's home network in the first place?
If only he had the chance to focus on actual important security issues instead of constant notifications about useless noise like the temperature of his Pi-Hole.
Hmm, anything like this can be used as part of side channel if an attacker is able to influence the temperature of Bob's RPi.