Two vulnerabilities have identical CVSS 9.0 scores. One has EPSS 0.85 and published PoC code; the other has EPSS 0.12 and no PoC. Which should be escalated first?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
- ACorrect: with equal CVSS scores, an EPSS of 0.85 plus public proof-of-concept code means exploitation is far more likely soon, so it goes first.
- BPlugin IDs are arbitrary scanner identifiers and say nothing about risk.
- CConfirming exposure matters, but it should not stall escalation of an item with strong exploitation signals.
- DEPSS 0.12 with no public exploit means this item is less likely to be exploited soon, so it comes second.