Elektrine lite

← Feed

@winterknight1337@infosec.exchange

Post #2977345

2026-05-13 13:42 UTC

@mysk@mastodon.social which scoring system is this using? By default, Tenable uses their VPR, which is a mix of CVSS and threat intel data figuring our probability of abuse. If they don’t think the bug will be abused, they’ll drop the rating. Even if it’s a high impact bug.

Replies (1)

  • @mysk@mastodon.social 2026-05-13 15:35

    @winterknight1337@infosec.exchange It seems to be rubbish. The vector doesn't reflect the attack at all. For example, the attack needs user interaction, but the vector doesn't include it. Anyhow, we will publish the blog and videos soon (targeting Friday). https://www.tenable.com/cve/CVE-2026-28910

    Open ##2977346