Skip to main content

Vulnerabilities – CVSS

Security within the IT infrastructure is a top priority for centron, particularly in the context of our ccloud³ cloud solution. To assess vulnerabilities efficiently and consistently, we use the Common Vulnerability Scoring System (CVSS), which was developed by the Forum of Incident Response and Security Teams (FIRST). This framework enables us to assess potential security vulnerabilities accurately and prioritise appropriate countermeasures.

Common Vulnerability Scoring System SIG

Why CVSS is important for the ccloud³

  1. Standardised security assessment

    By incorporating CVSS into ccloud³’s security strategy, we are able to assess vulnerabilities systematically and consistently. This ensures transparent communication between the IT Teams at centron and our customers.

  2. Clearly defined risk prioritisation

    CVSS helps centron to accurately assess the severity of a security vulnerability and to prioritise remedial actions based on this assessment. This assessment logic is incorporated into our ccloud³ security processes to ensure that the most serious vulnerabilities are addressed immediately

  3. Improving the security strategy

    The ccloud³ is designed to ensure the highest possible security standards. CVSS enables us to monitor the effectiveness of security measures and to improve them on an ongoing basis. This helps to ensure data integrity and the protection of our customers’ sensitive data.

How CVSS is applied in the ccloud³

1. Vulnerability Assessment

In ccloud³, every vulnerability detected is assessed using the CVSS framework. This assessment comprises three core components:

  • Base score: This determines the severity of the vulnerability itself.

  • Temporal value: Takes into account how the threat evolves over time.

  • Environmental impact: Determines the extent to which the vulnerability affects the specific environment of the ccloud³ and our customers.

2. Prioritisation and measures

Following the CVSS assessment, we initiate measures to rectify the vulnerability. The CVSS score is used to determine how urgently the vulnerability needs to be addressed:

  • Highly critical vulnerabilities: (CVSS score 9.0–10.0) are given the highest priority.

  • Moderate to critical vulnerabilities: (CVSS score 4.0–8.9) are also addressed promptly, but prioritised according to urgency.

  • Low-risk vulnerabilities: (CVSS score 0.1–3.9) are monitored and, where necessary, addressed in future updates.

By integrating the CVSS into centron and ccloud³’s security processes, we ensure that vulnerabilities are not only detected but also assessed objectively and prioritised. This enables centron to provide our customers with a reliable and highly secure cloud platform that can withstand the latest threats in the IT world.

Sources for identifying and deriving vulnerabilities

CategorySourceType of information
Rating systemsFIRST CVSS (https://www.first.org/cvss/))Severity rating
National CERTsCERT-Bund (BSI)Security alerts
National Situation CentresCyber Alliance Centre (CAZ) BavariaSituation reports, campaign alerts
EU authoritiesENISA Threat LandscapeThreat analyses
Vendor (Microsoft)Microsoft Security Response Centre (MSRC) – https://msrc.microsoft.comSecurity bulletins, patch information, CVEs
Vendor (Microsoft)Microsoft Security Update Guide – https://portal.msrc.microsoft.comStructured overview of vulnerabilities and updates
Vendor (Juniper)Juniper Security Advisories – https://advisory.juniper.net/Security bulletins for Junos OS & components
Vendor (Juniper)Juniper PSIRT (Product Security Incident Response Team)Coordinated vulnerability disclosures
Vendor (other)Vendor security bulletins for components in useProduct-related vulnerabilities
Open SourceGitHub Security AdvisoriesOSS vulnerabilities
Internal processesPSS-02 – Identification of vulnerabilitiesinternal assessment
Internal testsPenetration tests / scans (OPS-22 / OPS-25)technical findings
IncidentsSIM-01 / OPS-21Lessons learnt