Skip to content

Including EPSS in addition to CVSS? #161

@nmav

Description

@nmav

As mentioned in the training material CVSS has some issues, and in practice it results to a large list of vulnerabilities that need to be addressed even though if it doesn't overlap with the vulnerabilities list that are being exploited or are exploitable. There is the EPSS model from first.org that focuses on that problem. That is on making the list of vulnerabilities to be addressed smaller - i.e., more actionable. What are your thoughts in including this information in addition to CVSS?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions