Since 2015, Cyberwatch has been developing solutions to detect, prioritize, and remediate your IT vulnerabilities. This experience has allowed us to offer our clients several methods for CVE prioritization, ranging from the classic full CVSS score to more recent techniques like the EPSS score (Exploit Prediction Scoring System) or CISA KEV (Known Exploited Vulnerabilities). With the third version of the EPSS score released in 2023 and the addition of CISA KEV indicators to NVD entries, these latter techniques are becoming increasingly important for effective CVE prioritization.
However, an in-depth analysis of CVEs shows that using CVSS, EPSS, and CISA KEV scores in combination yields far superior results than using any of these scores in isolation.
In this article, Cyberwatch introduces a new vulnerability prioritization method called "3D prioritization," which combines the three dimensions of CVSS, EPSS, and CISA KEV.
Prioritizing CVEs with the 1D method: using the CVSS score
The traditional method of vulnerability analysis relies on the CVSS score. This score, often used based on data provided by authorities (the "base" score), must then be enriched with additional data—temporal and environmental—to provide a score tailored to each organization's specific needs.
This results in a prioritization method based on a single score, which we will call the 1D method.
The main advantage of this method is that it is simple to implement and provides a score recognized by the entire market: anyone working in vulnerability management knows the CVSS score, so it is never questioned by external auditors.
However, the disadvantage of this method is that it generates a significant workload for teams that have not properly defined their temporal or environmental data:
- More than 25,000 CVEs were published in 2022, which is over 68 new vulnerabilities per day;
- The average base CVSS score for CVEs published in 2022 is 7.8 out of 10, and more than 50% of CVEs have a score higher than 7 out of 10, meaning that over half of the vulnerabilities published in 2022 have a High or Critical severity (according to NVD base scales).
While using CVSS temporal and environmental data correctly is a very simple operation, it is rarely done in practice. The environmental component requires consulting the teams in charge of the assets, which introduces friction into the security maintenance process.
It is therefore easy to settle for a partial use of CVSS and end up with far too many vulnerabilities to address.
The 1D prioritization method is therefore ideal for experienced users or organizations with mature security maintenance processes, but it is complex for organizations just starting their vulnerability management journey.
This is especially true when organizations are actually looking to identify vulnerabilities exploited by hackers: out of the 224,000 CVEs in the NVD database, only 92,000 have at least one public attack kit (also known as an "exploit") available on the Internet.
Prioritizing CVEs by combining CVSS and EPSS scores: the 2D method
To help organizations better prioritize their vulnerabilities, FIRST, the creator of CVSS, introduced a new score in 2019 called the EPSS (Exploit Prediction Scoring System). This score aims to provide the probability that a vulnerability will be successfully exploited in the coming months.
This score is calculated using a mathematical model based on all CVEs published to date. The idea is to take the list of CVEs known to have been successfully exploited, define a list of markers for all CVEs, and then use a mathematical model from the XGBoost library to identify which values among these markers correlate with actually exploited CVEs.
However, like any method, this one can produce surprising results. For example, CVE-2020-1577 has an EPSS score of 79.06%, even though Microsoft states that exploitation of this vulnerability is unlikely.
Conversely, CVE-2021-36934, which Microsoft considers likely to be exploited, has an EPSS score of only 0.09%.
This provides a concrete example of a limitation of the EPSS score, which should not be used as a standalone metric, as doing so risks introducing new problems into vulnerability analysis and missing important vulnerabilities.
In this context, Cyberwatch recommends adopting a combined approach using both scores: focusing on CVEs that have a complete CVSS score greater than or equal to a certain value, while simultaneously filtering based on a relevant EPSS threshold. This method, which combines the two scores, will be referred to here as the 2D method.
The thresholds in question can be adapted to each information system. Graphically, the result of this prioritization strategy can be represented using data from FIRST, with thresholds of 20% for EPSS and 7 out of 10 for CVSS.
This approach is particularly well-suited to the complete CVSS score, which incorporates temporal and environmental scores. In the case of CVE-2020-1577, for example, the CVE will be dismissed for non-critical assets where environmental criteria are set to "low" or "medium" requirements, but will be considered a priority for critical assets where environmental requirements are set to "high" (as its complete CVSS score would then be 7.6 out of 10).
Nevertheless, the most attentive readers will point out that this approach does not resolve the case of CVE-2021-36934 due to its low EPSS score. This is addressed by the 3D method, which will be offered to all our clients in Cyberwatch version 13.
Prioritizing CVEs using CVSS, EPSS, and CISA KEV indicators: 3D prioritization
The CISA KEV is a catalog of vulnerabilities known to be actively exploited. This list is maintained by CISA (the Cybersecurity and Infrastructure Security Agency), while KEV is simply an acronym for Known Exploited Vulnerabilities. The CISA KEV contains the CVEs that authorities recommend addressing as soon as possible due to confirmed attacks.
Since 2022, as part of the BOD 22-01, certain U.S. authorities are required to provide an action plan for any CVE mentioned in this catalog.
The mere presence of a CVE in this catalog should trigger a rapid response to remediate it, regardless of its CVSS or EPSS scores.
Cyberwatch therefore recommends an approach that fully utilizes the 2D method, but enriched with CISA KEV information: a CVE will be considered a priority if its CVSS and EPSS scores exceed user-defined thresholds, or if it is mentioned in the CISA KEV. We call this the "3D method."
This 3D method allows for better management of situations like CVE-2021-36934, which has an EPSS of 0.09% but is specifically mentioned in the KEV catalog.
Going further: prioritizing CVEs using other catalogs like CERTFR-ALE
While the United States has the CISA KEV, France also has its own catalog with the CERTFR alerts from ANSSI (National Cybersecurity Agency of France), referenced in the CERTFR-<YEAR>-ALE format.
Contrary to what one might think, the CVEs mentioned in the CISA KEV and the CERTFR-ALE are not exactly the same: for example, the CERTFR-ALE will much more frequently mention CVEs related to open-source technologies widely used in French public administrations, such as Zimbra or GLPI. The same bias is found with the CISA KEV, which will mention CVEs related to technologies less common in French administrations, such as Cobalt Strike (an advanced software suite used for penetration testing).
For example, CVE-2022-35947, specific to GLPI, appears in the CERTFR-ALE but not in the CISA KEV. Similarly, CVE-2022-39197 for Cobalt Strike is present in the CISA KEV but not in the CERTFR-ALE.
We therefore recommend that analysts who follow ANSSI publications do not rely solely on the CISA KEV, but also use the CERTFR-ALE as a complementary source of information for their prioritization strategy.
Cyberwatch version 13 integrates this 3D prioritization method, with tracking for both CISA KEV and CERTFR-ALE catalogs
The vulnerability management software from Cyberwatch incorporates the results of our studies on the best ways to prioritize vulnerabilities and allows you to automatically configure a prioritization strategy based on CVSS, EPSS, and CISA KEV catalog data. These settings are directly accessible in the Criticality menu.
You can thus prioritize CVEs automatically using these new methods.
Discover our vulnerability detection and prioritization solution
Cyberwatch is a French software vendor specializing in vulnerability management. We offer a solution that is intuitive, easy to deploy, and allows you to detect and prioritize CVEs, as well as remediate them using a native Patch Management.
Our platform is built to help you save time in your security maintenance process and implements effective prioritization strategies.
Request a demo now using the dedicated form !
