Michael Schneider

166 Followers
164 Following
181 Posts
infosec, working at scip ag, classic car rally driver for teampaddymurphy.ie
Twitterhttps://twitter.com/0x6d69636b
GitHubhttps://github.com/0x6d69636b
LocationWinterthur, Switzerland
Companyhttps://www.scip.ch/en/?team.misc

I'm looking at the CVSS v4.0 specification - does anyone have a sound definition of what is a vulnerable system (VC, VI, VA)? Perhaps @kpwn?

I don't understand why, in the VMware Workstation example, the vulnerable system is the guest and the subsequent system is the host - and why, in a web service vulnerability, the underlying OS is usually part of the vulnerable system?