DEV Community

endoflife-ai
endoflife-ai

Posted on • Originally published at endoflife.ai

CVSS 9.8, EPSS 10.7%, and Confirmed Exploited: When the Three Scores Disagree

CVSS says how bad, CISA KEV says whether it is being exploited, EPSS says how likely it is next. On our Exploited & Unpatchable feed they openly disagree — a confirmed-exploited FortiOS flaw sits at 1.26% EPSS while a TeamCity flaw at CVSS 9.8 sits at 10.7%. How to read all three, and what changes when the software is end-of-life.

The three questions, precisely stated

Signal Question it answers Tense Who produces it
CVSS How bad would this be if exploited? Conditional The vendor (as CNA) and/or NVD
CISA KEV Is this being exploited, in reality? Past & present CISA, on evidence
EPSS How likely is exploitation in the next 30 days? Forecast FIRST.org, a daily model

What's covered

  • The three questions, precisely stated
  • Twelve vulnerabilities, scored three ways
  • Case 1: confirmed exploited, lowest probability in the set
  • Case 2: the highest severity, near the bottom for probability
  • Case 3: the medium-severity flaw ransomware crews preferred
  • The fourth disagreement: the scorers disagree with each other
  • The column that changes the answer
  • How to actually triage

Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-scores-disagree

Top comments (0)