<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic About CVSS version in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/about-cvss-version/m-p/1237684#M125101</link>
    <description>&lt;P&gt;Hello PaloAlto Networks Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What version of CVSS is listed in Palo Alto Networks Security Advisories?&lt;/P&gt;
&lt;P&gt;Please tell me which version it is, such as CVSS v3 or v4.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 11 Sep 2025 01:11:25 GMT</pubDate>
    <dc:creator>Y.Narita347153</dc:creator>
    <dc:date>2025-09-11T01:11:25Z</dc:date>
    <item>
      <title>About CVSS version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-cvss-version/m-p/1237684#M125101</link>
      <description>&lt;P&gt;Hello PaloAlto Networks Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What version of CVSS is listed in Palo Alto Networks Security Advisories?&lt;/P&gt;
&lt;P&gt;Please tell me which version it is, such as CVSS v3 or v4.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 01:11:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-cvss-version/m-p/1237684#M125101</guid>
      <dc:creator>Y.Narita347153</dc:creator>
      <dc:date>2025-09-11T01:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: About CVSS version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-cvss-version/m-p/1237744#M125102</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/441516037"&gt;@Y.Narita347153&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Alto Networks has adopted CVSS v4.0 as its primary scoring system for new security advisories.&lt;/P&gt;
&lt;P&gt;While older advisories still list scores using CVSS v3.1, all new advisories now feature the updated CVSS v4.0 metrics and a vector string, in addition to other context-specific ratings like Urgency, Response Effort, and Recovery.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/product-security-assurance" target="_blank"&gt;https://www.paloaltonetworks.com/product-security-assurance&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"We use&amp;nbsp;&lt;A href="https://www.first.org/cvss/specification-document" target="_blank" rel="noopener"&gt;CVSS version 4.0&lt;/A&gt;&amp;nbsp;(CVSS-B, and CVSS-BT scores) to score vulnerabilities and consider several factors such as active exploitation, customer exposure, and public disclosure timelines while prioritizing response actions for issues. The Base Score (CVSS-B) reflects the severity of a vulnerability according to its intrinsic characteristics which are constant over time. The Threat Metrics (CVSS-BT) adjust the severity of a vulnerability based on factors, such as the availability of proof-of-concept code or active exploitation."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 09:52:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-cvss-version/m-p/1237744#M125102</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-09-11T09:52:11Z</dc:date>
    </item>
  </channel>
</rss>

