Feb 22, 2021

Blindspot in Using CVSS for Vulnerability Prioritization

Just read the article about "Why You Need to Stop Using CVSS for Vulnerability Prioritization" from Tenable.

After using KennaSecurity, I learn that there is vulnerability management blindspot if you are using CVSS for vulnerability prioritization.

A simple scenario here:

The vulnerability scanning tool discovers 2 CVE at an external facing host (Debian OS):  CVE-2020-8617 (cvss:5) and CVE-2020-1472 (cvss:9). 

Conclusion: Asset priority is very important/useful while doing vulnerability prioritization. Make sure your vulnerability management tool does include any form of asset prioritization.