CVE, CVSS, and vulnerabilities
In cybersecurity, we have formal systems for classifying security vulnerabilities in networks and applications. Known vulnerabilities are recorded in MITRE’s Common Vulnerabilities and Exposures database, or CVE for short (https://www.cve.org/). CVE records are classified according to MITRE’s CVSS (https://nvd.nist.gov/vuln-metrics/cvss). Also, known exploits are classified with EPSS (https://www.first.org/epss/). MITRE ATT&CK is a database for classifying known exploits to computer systems and networks (https://attack.mitre.org/).
So, MITRE is the organization that helps cybersecurity professionals of all kinds understand vulnerabilities and exploits. The knowledge in MITRE’s databases grows constantly, every day. MITRE’s databases are on the web, freely available for anyone to use as a reference. As a cloud pentester, your job is to discover vulnerabilities and exploits in the cloud networks you test so that the organization...