An enterprise SOC vulnerability report lists an internet-facing web application flaw as CVSS 6.1, EPSS 0.94, and included in CISA KEV. The application owner asks why it should be remediated before higher-CVSS internal findings. Which reporting rationale best justifies the escalation?
Select an answer to reveal the explanation.
Short Explanation
Think of CVSS like a car’s crash rating and EPSS like the odds that a thief is already trying to break in. You don’t wait for a higher crash score when the car is already being targeted. KEV and EPSS tell you the threat is active, so your report should say fix it now.
Full Explanation
Vulnerability communication should translate risk into prioritized action. CVSS describes severity under defined conditions, while EPSS estimates near-term exploitation likelihood and KEV records confirmed active exploitation. When a lower-severity item appears in KEV with high EPSS, the report can justify expedited remediation because real-world exploitation evidence changes operational risk even if base severity is moderate. A scanner’s unauthenticated status may reduce certainty or alter findings, but it does not by itself convert a medium finding into a critical one; it affects confidence, not the exploitation signal. EPSS is not limited to internet-facing assets, and KEV is not limited to end-of-life products; both are CVE-centric indicators that can apply across supported and unsupported environments. Internet exposure can raise environmental risk, but CVSS temporal and environmental metrics are not automatically increased; they require explicit analyst-assessed factors such as exploit maturity, remediation level, and asset criticality. Exam caveat: prioritize documented exploitation likelihood and active-exploitation listings over raw CVSS when the question asks for the next operational action. Operational check: cite the CVE, CVSS, EPSS percentile, KEV date, asset exposure, and required mitigation deadline in the escalation ticket.