<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability-Management on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/vulnerability-management/</link><description>Recent content in Vulnerability-Management on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/vulnerability-management/index.xml" rel="self" type="application/rss+xml"/><item><title>CVSS (Common Vulnerability Scoring System)</title><link>https://lesitedefrancois.be/en/security/cvss/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/security/cvss/</guid><description>&lt;p&gt;&lt;strong&gt;CVSS (Common Vulnerability Scoring System)&lt;/strong&gt; is an open framework published by FIRST (Forum of Incident Response and Security Teams) for characterising and communicating the technical severity of software vulnerabilities through a standardised numerical score. The current version is &lt;strong&gt;CVSS v4.0&lt;/strong&gt; (released November 2023), which introduced a fourth metric group and clarified nomenclature to address the persistent misuse of CVSS Base scores as standalone risk measurements. CVSS scores appear in the NVD (National Vulnerability Database), CVE entries, scanner output from Qualys, Tenable, Rapid7, Grype, and Trivy, and in compliance frameworks that specify remediation SLAs based on severity bands — &amp;ldquo;critical (9.0–10.0) within 15 days, high (7.0–8.9) within 30 days.&amp;rdquo; The score ranges from 0.0 (no impact) to 10.0 (maximum severity) and maps to five qualitative ratings: None (0.0), Low (0.1–3.9), Medium (4.0–6.9), High (7.0–8.9), and Critical (9.0–10.0).&lt;/p&gt;</description></item><item><title>KEV (CISA Known Exploited Vulnerabilities Catalog)</title><link>https://lesitedefrancois.be/en/security/kev/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/security/kev/</guid><description>&lt;p&gt;The &lt;strong&gt;CISA Known Exploited Vulnerabilities (KEV) Catalog&lt;/strong&gt; is a living database maintained by the US Cybersecurity and Infrastructure Security Agency that lists CVEs for which CISA has obtained reliable evidence of active exploitation in the wild. It was established under &lt;strong&gt;Binding Operational Directive 22-01 (BOD 22-01)&lt;/strong&gt;, issued in November 2021, which requires all US Federal Civilian Executive Branch (FCEB) agencies to remediate KEV-listed vulnerabilities within prescribed timeframes — typically 2 weeks for critical vulnerabilities and up to 6 months for older ones. A vulnerability must meet three criteria to be added: it must have a &lt;strong&gt;CVE ID&lt;/strong&gt;, there must be &lt;strong&gt;reliable evidence of exploitation in the wild&lt;/strong&gt; (not just a proof-of-concept or theoretical risk), and there must be &lt;strong&gt;clear remediation guidance&lt;/strong&gt; available. CISA accepts nominations from the public and adds vulnerabilities continuously; the catalog is available in CSV and JSON formats at a stable URL, making it machine-consumable for integration into vulnerability management platforms and asset inventory tools.&lt;/p&gt;</description></item></channel></rss>