Zero Day Room
Live
How Cvss And Epss Scoring Work
Photo: FIRST (Forum of Incident Response and Security Teams) (CC BY-SA 4.0), via Wikimedia Commons

How Cvss And Epss Scoring Work

SubjectCVSS and EPSS scoring methodologies
Primary standardCVSS v3.1
PurposeCVSS measures severity
InputsCVSS uses base metrics
OutputCVSS outputs a vector string

Origin and history

The Common Vulnerability Scoring System (CVSS) originated from work within the United States in the early 2000s, specifically developed by the National Infrastructure Advisory Council (NIAC). Its initial version was released in the first decade of the 21st century to provide a standardized method for assessing software vulnerability severity. The Exploit Prediction Scoring System (EPSS) is a more recent model, emerging from collaborative research within the Forum of Incident Response and Security Teams (FIRST) in the 2010s. EPSS was created to address a critical gap in prioritization that CVSS alone could not fill. Its development was driven by the need to incorporate real-world threat intelligence and the likelihood of exploitation into risk calculations. Both frameworks are now maintained and updated by FIRST, an international consortium of security teams.

What it is for

CVSS is designed to assign a standardized, qualitative severity score to a software vulnerability based on its intrinsic characteristics and potential impact. This score, ranging from 0.0 to 10.0, helps organizations understand the potential technical severity of a vulnerability in isolation. EPSS is designed specifically to predict the probability that a vulnerability will be exploited in the wild within the next 30 days. Its purpose is to provide a data-driven, probabilistic score to help security teams prioritize remediation efforts based on actual threat activity. Together, these systems aim to move beyond subjective judgment and provide consistent, comparable metrics for vulnerability management. They serve as critical inputs for enterprise risk management programs and security operations center workflows.

Overview

CVSS operates by calculating scores across three metric groups: Base, Temporal, and Environmental. The Base metrics evaluate intrinsic qualities like attack vector, complexity, and impact on confidentiality, integrity, and availability. Temporal metrics adjust the score for factors like the existence of an exploit or patch, while Environmental metrics account for the specific context of an organization's infrastructure. The final score is represented as a vector string and a numerical severity rating (Low, Medium, High, Critical). EPSS, in contrast, is a machine learning model that consumes a wide array of data sources, including CVE descriptions, threat intelligence feeds, and historical exploitation data. It outputs a probability score between 0 and 1, representing the estimated chance of exploitation, which is intended to be used alongside CVSS severity scores.

What to know

It is essential to know that a high CVSS score does not necessarily mean a vulnerability will be exploited; many high-severity vulnerabilities are never weaponized. Conversely, a vulnerability with a moderate CVSS score but a very high EPSS probability should be treated as a pressing priority. Organizations must understand that CVSS assesses "severity" while EPSS estimates "likelihood," and effective risk is a function of both. The CVSS Environmental score is crucial for tailoring the generic Base score to your specific technical environment and security requirements. EPSS scores are dynamic and can change daily as new threat intelligence is ingested into the model. Implementing these scores requires integrating them into vulnerability management platforms and establishing internal policies for how different score combinations trigger remediation actions.

Common questions

A common question is whether a CVSS score of 9.0 should always be patched before a score of 7.0, to which the answer is no, as business context and exploit likelihood must be considered. Practitioners often ask how EPSS gathers its data, which includes sources like dark web chatter, exploit kit integrations, and active scanning activity from internet-wide sensors. Many wonder if they should use EPSS instead of CVSS, but the guidance is to use them conjunctively, as they measure different but complementary aspects of risk. Questions frequently arise about the accuracy of EPSS, which, like any predictive model, provides probabilities and is not a definitive forecast. Organizations also commonly inquire about the cost of implementing these systems, which primarily involves the operational overhead of integrating the scores into existing workflows rather than direct licensing fees.

Pros and cons

A major pro of CVSS is its deep granularity and transparency, allowing technical teams to understand exactly which vulnerability properties led to a given score. A significant con of CVSS is that its widespread use as a sole prioritization metric often leads to "critical fatigue," where teams are overwhelmed by a long list of high-severity flaws with no guidance on which are truly threatening. A pro of EPSS is its direct incorporation of real-world threat data, which can dramatically focus remediation efforts on the vulnerabilities attackers are actually using. A key con of EPSS is its opacity as a machine learning model; users cannot easily deconstruct why a particular probability was assigned, which can reduce trust. A common mistake is to adopt EPSS scores without establishing an internal threshold for action, leading to confusion over how to interpret a probability of 0.2 versus 0.4. Organizations often regret relying solely on CVSS when they later discover a widely exploited vulnerability had only a moderate base score.

Who it suits

CVSS is suited for technical security analysts and software developers who need to understand the fundamental technical characteristics and potential impact of a vulnerability during assessment or patch development. EPSS is particularly suited for security operations center managers, vulnerability management program leads, and resource-constrained IT teams who must make rapid, data-driven decisions about remediation order. Large enterprises with mature vulnerability management programs benefit from using both systems in tandem to balance intrinsic severity with threat intelligence. Organizations in highly regulated industries may find CVSS Environmental scores essential for demonstrating compliance with specific security controls. Teams with advanced data science capabilities may leverage the raw EPSS model outputs for further custom analysis and integration with internal threat feeds.

Latest How Cvss And Epss Scoring Work news

Latest reporting