Lesson summary
CVSS, EPSS, and KEV are useful signals with different meanings. This lesson teaches how to preserve score source and date, interpret a vector, and combine public signals with local applicability, exposure, business impact, controls, and remediation context.
Learning objectives
- Explain what CVSS measures and read vector context.
- Explain EPSS score, percentile, and associated date.
- Explain what KEV inclusion indicates.
- Separate technical severity, modeled exploitation likelihood, known exploitation, local applicability, and business priority.
- State local evidence still required before treatment decisions.
Prerequisites
Basic CVE and advisory familiarity is useful. Completing Validating Vulnerability Applicability helps but is not required. No advanced statistical knowledge is required.
Why these signals matter
Signals can guide attention, but they do not replace judgment. CVSS does not prove exploitation or equal business risk. EPSS does not prove exploitation or guarantee a future outcome for one asset. KEV does not prove local deployment, local applicability, or compromise. Absence from KEV does not prove exploitation has not occurred.
Core concepts
CVSS records a version, base score, severity band, vector, attack vector, attack complexity, privileges required, user interaction, scope where applicable, and confidentiality, integrity, and availability impact. Vendor and NVD values must remain separately attributed; differing values should not be averaged. EPSS is a modeled probability signal with a score, percentile, population-relative meaning, and date; values change over time. KEV catalog inclusion is evidence that known exploitation has been recognized, with source and date context.
Important distinctions
Technical severity differs from exploitability characteristics, modeled exploitation likelihood, known exploitation evidence, local exposure, local exploitation, local compromise, business impact, and remediation priority. Local applicability must be validated before treatment conclusions. No single signal creates a universal priority result.
Guided interpretation workflow
- Confirm the vulnerability and affected product scope, then validate local applicability.
- Record CVSS version, score, vector, and source; interpret the vector rather than only the score.
- Record current EPSS score, percentile, and date.
- Confirm KEV inclusion and its source context.
- Review credible exploit evidence, local exposure, business service, controls, remediation availability, uncertainty, and missing evidence.
- Produce a bounded treatment recommendation and reassess when source values or local context change.
Fictional worked example
Issue A has CVSS 9.8, a network vector, low EPSS, no KEV inclusion, confirmed applicability on an internally isolated non-critical asset, and strong access restrictions. It is technically severe and still needs treatment, but evidence does not automatically establish emergency priority. Issue B has CVSS 6.5, KEV inclusion, credible exploitation evidence, an internet-facing applicable asset, and reliable remediation; accelerated treatment is justified. Issue C has CVSS 8.1, EPSS that was high on an earlier date but lower today, unknown exact local version, no confirmed exposure, and no KEV inclusion; priority remains provisional pending version and exposure evidence.
Decision exercise
Map CVSS, vector, EPSS score and percentile, KEV inclusion, local applicability, local exposure, and asset criticality to the question each answers. Then choose emergency review, accelerated treatment, a validated maintenance window, temporary controls with scheduled remediation, or collect more evidence for Issues A, B, and C. Give a short evidence-based reason.
Knowledge checks
- Does a high CVSS prove exploitation? No; it describes technical severity and characteristics, not observed exploitation.
- Why retain an EPSS date? Scores change, so the date is part of the interpretation.
- Does KEV prove local compromise? No; validate local product, version, exposure, and telemetry separately.
- Can a lower CVSS issue be urgent? Yes, when known exploitation, exposure, business service, and remediation context support urgency.
Answer explanations
Good answers identify the signal, its source and date, its limit, and the next local evidence needed. Correct review answers do not demonstrate mastery, certification, or operational authorization.
Common misconceptions
The highest CVSS always patches first; EPSS proves exploitation; EPSS is timeless; KEV means the local asset is compromised; absence from KEV means no exploitation; vendor and NVD scores should be averaged; or one score replaces local applicability review.
Practical takeaway
Keep a short signal note: CVSS source and vector, EPSS score and date, KEV state, exploit evidence, local applicability, exposure, business context, controls, owner, uncertainty, and next evidence request.
Next: This curriculum will continue with From Vulnerability Evidence to Priority.
Related content
Knowledge: Patch Window Prioritization, Exploit Evidence Validation, Source Reliability and Evidence Grading, Conflicting-Source Resolution.
Tool and Practice: CVSS Calculator, Prioritize Three CVEs.
Intelligence: Curated CVEs, KEV.
Limitations
Public scores and catalogs can be incomplete, stale, or differently scoped. This educational lesson does not prove local exploitation, compromise, business impact, or complete coverage.
Last reviewed: Unknown. Recheck current sources and local evidence before acting.