From b80c21f8d962213bad7f38fe71a829662ea05f48 Mon Sep 17 00:00:00 2001 From: Anna Levchenko <71260515+annlev@users.noreply.github.com> Date: Tue, 19 Mar 2024 20:33:37 +0200 Subject: [PATCH] TCR-378 Adjust the Vulnerability Coverage section in the ELS documentation TCR-378 Adjust the Vulnerability Coverage section in the ELS documentation --- docs/extended-lifecycle-support/README.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/docs/extended-lifecycle-support/README.md b/docs/extended-lifecycle-support/README.md index 12205b11..97fe0637 100644 --- a/docs/extended-lifecycle-support/README.md +++ b/docs/extended-lifecycle-support/README.md @@ -6,9 +6,11 @@ Our ELS service is designed to provide solutions for organizations that are not ### Vulnerability coverage -TuxCare employs the Common Vulnerability Scoring System (CVSS v3) to assess the severity of security vulnerabilities. Our severity rating system for patching vulnerabilities integrates both NVD scoring and vendor scoring (when available). When the vendor's score is lower than the NVD score, we give priority to the NVD score. +TuxCare employs the Common Vulnerability Scoring System (CVSS v3) to assess the severity of security vulnerabilities. Our severity rating system for patching vulnerabilities integrates both NVD scoring and vendor scoring (when available). When the vendor's score is lower than the NVD score, we give priority to the NVD score. -TuxCare Extended Lifecycle Support, by default, provides security patches for High and Critical vulnerabilities (with a 7+ CVSS score). For vulnerabilities rated as Medium (4.0 to 6.9), and/or when patches are required for FIPS-certified deployments, custom coverage options are available. Specific details regarding these coverage options and their pricing can be obtained by contacting our sales team. +TuxCare Extended Lifecycle Support automatically provides security patches for High and Critical vulnerabilities with CVSS scores of 7+. For Medium-severity vulnerabilities (CVSS scores 4.0 to 6.9), TuxCare actively monitors and selectively patches those with potentially underrated CVE impacts and/or risks to TuxCare customers. + +Custom coverage options include patches for FIPS-certified deployments and a 10-pack of customer-selected patches for CVEs outside the standard ELS scope. For detailed information on these coverage options and their pricing, please contact our sales team ### Target response times