DECISION SUPPORT / PUBLIC DATA
From CVE to a priority
you can explain.
Technical severity, exploitation probability, confirmed active exploitation and your asset context — without a black box.
METHODOLOGY v2.0
Rule-based remediation priority
The result orders remediation work. It is not a probability of exploitation, compromise or loss.
- Exploitation evidenceCISA KEV first; EPSS probability is a likelihood input. Percentile is informational only.
- Technical severityCVSS Base severity; missing CVSS is treated as a data gap, not a low score.
- Asset contextComponent reachability and business criticality can escalate; verified relevant controls can reduce one level.
Base from CVSS: ≥9.0 → P2; 7.0–8.9 → P3; below 7.0 → P4. Missing CVSS → DATA.
Modifiers: EPSS ≥10% raises one level; internet reachability or critical asset raises one; verified relevant controls on a segmented/isolated component reduce one.
P1: applicable KEV with an internet-reachable component or critical asset and no verified mitigation; non-KEV reaches P1 through the documented modifiers.
P2 floor for KEV: other applicable KEV records cannot be reduced below P2 by controls.
Unknown applicability: remediation priority is provisional and a separate V1/V2 verification priority is shown.
Rounding: none. The model uses decision rules; EPSS is displayed without rounding to 100%.