In a landscape where security vulnerabilities multiply daily, how to decide which ones to correct first? The answer lies in two basic standards: the Common Vulnerability Scoring System (CVSS) and the Exploit Prediction Scoring System (EPSS).
The Numbers of Vulnerability
- Over 25,000 new CVEs published in 2023
- Only 2% of vulnerabilities are actually exploited in real attacks
- 75% of organizations struggle to prioritize security patches
- Average patch time for critical vulnerabilities: 60 days
CVSS: The Standard De Facto
The CVSS (currently version 4.0) provides a standardized framework to assess the severity of security vulnerabilities. It is based on three main metrics:
1. Basic Metrics
- Attack Carrier (Network, Adjacent, Local, Physical)
- Attack complexity
- Privileges required
- User interaction needed
- Impact on Confidentiality, Integrity and Availability
2. Time Metrics
- Maturity of exploit code
- Level of remediation available
- Report confidence
3. Environmental Metrics
- Modified safety requirements
- Modified Attack Vector
- Modified Attack Complexity
EPSS: The New Frontier of Prioritization
The EPSS completes the CVSS by predicting the likelihood of a vulnerability actually being exploited over the next 30 days.
Benefits of EPSS
- Machine Learning Prediction
- Daily Score Update
- Integration with threat intelligence data
- More precision in prioritisation
Why EPSS Overcomes CVSS Limits
CVSS Limits
- Lack of Royal Context CVSS assesses theoretical severity, not real risk (NIST IR 8409, Section 3.2) It does not consider the current context of static Score threats that do not reflect the evolution of threats (FIRST CVSS v4.0 Limitations)
- Vulnerability overestimation According to NVD Dashboard, in 2023 17.5% of vulnerabilities received a CVSS score > 9.0 Prioritization to Prediction Report Volume 9 shows that only 2-5% of critical CVSS vulnerabilities are actually exploited Second Gartner, 90% of vulnerabilities exploited had a CVSS score below 9.0
- Wasted Resources Ponemon Institute Cost of a Data Breach 2023 reports that organizations employ on average 60 days to correct critical vulnerabilities RAND Corporation Research estimates that companies spend 58% of the patching budget on vulnerabilities that will never be exploited
Benefits of EPSS demonstrated by data
- Data Based Prediction EPSS Model Performance shows an accuracy of 86% in the prediction of Database exploits of over 300,000 vulnerabilities analyzed (EPSS Dataset) Daily update based on 25+ threat intelligence feed (EPSS Architecture)
- Operational Efficiency CISA KEV Catalog confirms that EPSS correctly identifies 91% of actively exploited vulnerabilities Cyentia Research demonstrates a reduction of 82% in the volume of vulnerabilities to manage priority NIST Case Study highlights a 70% improvement in the efficiency of patching
- Measured ROI EPSS Adoption Survey shows an average saving of 45% on remediation costs 63% reduction in patching time for critical vulnerabilities (Kenna Security Report) Forrester Total Economic Impact Study quantify a 287% ROI in the adoption of predictive systems such as EPSS
Case Study: EPSS vs CVSS in Practice
A recent FIRST study of 100 enterprise organizations has shown that:
- Only 4.1% of critical CVSS vulnerabilities have actually been exploited
- EPSS correctly predicted 86.3% of exploits in the following month
- EPSS organizations reduced the average patching time by 61.5%
How to Use Both Standards
Integrated Approach
- CVSS to evaluate intrinsic gravity Score from 0.0 to 10.0 Evaluation of potential impact Analysis of technical complexity
- EPSS to evaluate the probability of exploitation Percentage from 0 to 100 Real Data-based forecasts Active exploitation trends
Recommended Formula for Prioritization
Priority = (CVSS Base Score * 0.6) + (EPSS Score * 0.4)
Best Practices for Implementation
- Process automation Integration with vulnerability Dashboard Auto Alert monitoring scanners for high scores
- Remediation policy based on thresholds Critics: CVSS ≥ 9.0 or EPSS ≥ 50% High: CVSS ≥ 7.0 or EPSS ≥ 30% Medium: CVSS ≥ 4.0 or EPSS ≥ 10%
- Documentation and reporting Drawing decisions Analysis of trends Performance metrics
Tools and Resources
CVSS calculators
- FIRST CVSS Calculator
- NVD CVSS Calculator
- Red Hat CVSS Calculator
EPSS resources
- FIRST EPSS Portal
- EPSS API Documentation
- EPSS Daily Scores
Framework and Integration Tool
Reference Documents and Guides
CVS
EP
- EPSS Model Documentation
- EPSS Data Sources
- Cyentia Research Institute
Call to Action
- Evaluate the implementation of both standards in your organization
- Automated the process of scoring and prioritization
- Format the team on the correct interpretation of scores
- Share your experiences with the community




