Scenario: A cybersecurity analyst at a regional Air Traffic…
Scenario: A cybersecurity analyst at a regional Air Traffic Control (ATC) center identifies a critical vulnerability (Buffer Overflow) in the software managing the ADS-B telemetry feed. The NVD (National Vulnerability Database) has assigned this vulnerability a Base Score of 9.8 (Critical) because it is remotely exploitable and has a high impact on Availability. However, the analyst notes the following context: Temporal Factor: A stable, vendor-verified patch was released 48 hours ago (Remediation Level). Environmental Factor: The ATC center has implemented a high-availability “Hot Standby” system and hardware-based data diodes that prevent external write access to the telemetry bus (Confidentiality/Availability Requirements and Modified Base Metrics). Question: When the analyst calculates the Full CVSS Score (Base + Temporal + Environmental), how will the final score most likely compare to the original 9.8 Base Score, and why?
Read Details