Security News > 2023 > July > Relying on CVSS alone is risky for vulnerability management

A vulnerability management strategy that relies solely on CVSS for vulnerability prioritization is proving to be insufficient at best, according to Rezilion.
Relying solely on a CVSS severity score to assess the risk of individual vulnerabilities was shown to be equivalent to randomly selecting vulnerabilities for remediation.
Throughout the new research, Rezilion's vulnerability researchers unveiled more than 30 actively exploited vulnerabilities with a high EPSS score that were not listed in the CISA KEV catalog, highlighting the coverage gap within the CISA KEV catalog.
"These findings accentuate the need for considering more than just one metric for effective vulnerability management," said Yotam Perkal, Director of Vulnerability Research with Rezilion.
The KEV catalog alone is insufficient due to the delay in adding newly discovered vulnerabilities.
A patching strategy that considers CVSS, internal environment context, and additional threat intelligence sources such as CISA KEV combined with EPSS, can assist organizations in making informed, risk-based vulnerability management decisions and improve the overall security posture of their organization.
News URL
https://www.helpnetsecurity.com/2023/07/31/cvss-vulnerability-strategy/
Related news
- Critical Apache Roller Vulnerability (CVSS 10.0) Enables Unauthorized Session Persistence (source)
- Critical Erlang/OTP SSH Vulnerability (CVSS 10.0) Allows Unauthenticated Code Execution (source)
- Over 100,000 WordPress Sites at Risk from Critical CVSS 10.0 Vulnerability in Wishlist Plugin (source)
- Review: Effective Vulnerability Management (source)
- Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT (source)
- Beyond Vulnerability Management – Can You CVE What I CVE? (source)
- Microsoft Fixes 78 Flaws, 5 Zero-Days Exploited; CVSS 10 Bug Impacts Azure DevOps Server (source)
- Why CVSS is failing us and what we can do about it (source)
- ThreatLocker Patch Management: A Security-First Approach to Closing Vulnerability Windows (source)