Related Experiment Video
Updated: Jan 10, 2026

Assays for the Identification of Novel Antivirals against Bluetongue Virus
Published on: October 11, 2013
Quantifying medical device cybersecurity risk with CVSS BTE
Lorenzo Bracciale1,2, Sasha Riozzi3, Giorgia Panico3,4
1Department of Electronic Engineering, University of Rome Tor Vergata, Rome, Italy. lorenzo.bracciale@uniroma2.it.
The Common Vulnerability Scoring System (CVSS) 4.0's full scoring (Base, Threat, Environmental) improves cybersecurity vulnerability prioritization. Applying this BTE scoring to medical devices reveals more accurate and actionable risk assessments, especially for safety-critical systems.
Area of Science:
- Cybersecurity
- Information Security
- Medical Device Security
Background:
- The Common Vulnerability Scoring System (CVSS) is the industry standard for assessing cybersecurity vulnerability severity.
- Current practices often misuse CVSS by relying solely on the Base Score, neglecting contextual Threat and Environmental metrics.
- This limited approach leads to suboptimal prioritization, particularly in safety-critical sectors like healthcare.
Purpose of the Study:
- To conduct the first large-scale application of the full CVSS 4.0 Base, Threat, and Environmental (BTE) scoring.
- To evaluate the impact of BTE scoring on vulnerability prioritization within a dataset of medical device vulnerabilities.
- To explore the automation potential for Threat and Environmental metric compilation.
Main Methods:
- Large-scale application of CVSS 4.0 BTE scoring to a comprehensive dataset of medical device vulnerabilities.
- Partial automation of the Threat metric group using structured data sources.
- Semi-automatic compilation of Environmental metrics using defined environmental profiles (e.g., home vs. hospital care).
Main Results:
- CVSS 4.0 BTE scoring significantly alters vulnerability prioritization compared to Base Score alone.
- Threat metrics can be partially automated, streamlining the assessment process.
- Environmental profiles facilitate semi-automatic compilation of Environmental metrics, enhancing contextual risk assessment.
Conclusions:
- Full CVSS 4.0 BTE scoring provides a more accurate and actionable representation of cybersecurity risk.
- The methodology enhances prioritization, especially crucial for safety-critical domains such as healthcare.
- Automation strategies for Threat and Environmental metrics show promise for practical implementation.
More Related Videos
Related Concept Videos
Methods of Documentation V: CBE
In CBE, healthcare professionals establish predefined standards of practice that define what constitutes...
Types of Biopharmaceutical Studies: Controlled and Non-Controlled Approaches
Non-controlled studies, commonly employed for initial exploration, lack a control group, rendering them susceptible to biases and external influences. In contrast,...
Guidelines and Strategies for Safe Computer Charting
Maintain Confidentiality and Security:
Imaging Studies for Cardiovascular System VI: Calcium -Scoring CT
Healthcare Associated Infections II: Preventive Measures
The best practices for preventing healthcare-associated infections include hand hygiene, patient risk...
Factors Affecting the Risk of Infection
The integrity and count of the white blood cells help the body resist pathogens and fight infection. When impaired, it reduces the body's resistance to pathogens. The acidic pH levels of the gastrointestinal, genitourinary tracts, and skin...

