RSA Security Advisories Severity Rating
Originally Published: 2009-07-08
Article Number
Applies To
Resolution
Severity Rating
A security vulnerability is classified by its severity rating, which is determined by many factors, including the level of effort required to exploit a vulnerability as well as the potential impact to data or business activities from a successful exploit. RSA currently uses the Common Vulnerability Scoring System version 3.0 (CVSS v3.0) to identify the severity level of identified vulnerabilities. The full standard, which is maintained by the Forum of Incident Response and Security Teams (FIRST), can be found at https://www.first.org/cvss.When and where applicable, RSA Security Advisories will provide the CVSS v3.0 Base Score, corresponding CVSS v3.0 Vector and the CVSS v3.0 Severity Rating Scale for identified vulnerabilities. RSA recommends that all customers take into account both the Base Score and any Temporal and/or Environmental Scores that may be relevant to their environment to assess their overall risk.
| CVSS v3 Base Score Metrics | Description | Possible Values | |
|---|---|---|---|
| Exploitability Metrics | Related exploit range | AttackVector (AV) | P = Physical access, L = Local access, A = Adjacent network, N = Network |
| Attack complexity | AttackComplexity (AC) | L = Low, H = High | |
| Level of privileges required | PrivilegesRequired(PR) | N = None required, L = Low privileges required, H = High privileges required | |
| User interaction | UserInteraction (UI) | N = None, R = Required | |
| Scope Metric | Scope | Scope (S) | U = Unchanged. No scope change, C = Changed. Scope changed |
| Impact Metrics | Confidentiality impact | ConfImpact (C) | N = None, L = Low, H = High |
| Integrity impact | IntegImpact (I) | N = None, L = Low, H = High | |
| Availability impact | AvailImpact (A) | N = None, L = Low, H = High | |
Severity
The Severity field in an RSA Security Advisory is defined with the value of Critical, High, Medium or Low based on the highest CVSSv3 score of the CVEs associated with the advisory. The severity level is determined based on the criteria below.| Severity Level | Criteria |
|---|---|
| Critical | CVSSv3 base score is greater than or equal to 9.0 |
| High | CVSSv3 base score is greater than or equal to 7.0 but less than 9.0 |
| Medium | CVSSv3 base score is greater than or equal to 4.0 but less than 7.0 |
| Low | CVSSv3 base score is less than or equal to 3.9 |
Related Articles
Reporting Engine service is not running due to reportstatusmanager.h2.db corrupt 14Number of Views RSA Announces Critical Security Updates for RSA ID Plus Components - RSA Authentication Manager and RSA Identity Router 858Number of Views RSA SecurID Hardware Appliance Component Updates 502Number of Views RSA MFA Agent for Windows will not run due to error "This module is blocked from loading into the Local Security Authority" 850Number of Views How to Connect to the RSA Authentication Manager Database Using PostgreSQL (psql) 1.83KNumber of Views
Trending Articles
Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA Authentication Manager 8.9 Release Notes (January 2026) AFX Server Fails to Start with 'Could Not Build a Validated Path' and 'Timed Out Waiting for AFX Applications to Start' in… AFX Server stuck in 'Not running' State, with error 'timed out waiting for AFX applications to start' Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?