arXiv · 2411.02618
Efficacy of EPSS in High Severity CVEs found in KEV
Abstract
The Exploit Prediction Scoring System (EPSS) is designed to assess the probability of a vulnerability being exploited in the next 30 days relative to other vulnerabilities. The latest version, based on a research paper published in arXiv, assists defenders in deciding which vulnerabilities to prioritize for remediation. This study evaluates EPSS's ability to predict exploitation before vulnerabilities are actively compromised, focusing on high severity CVEs that are known to have been exploited and included in the CISA KEV catalog. By analyzing EPSS score history, the availability and simplicity of exploits, the system's purpose, its value as a target for Threat Actors (TAs), this paper examines EPSS's potential and identifies areas for improvement.
Explore related subjects
Keep this discovery
Rianna Parla. 2024-11-04. Efficacy of EPSS in High Severity CVEs found in KEV. https://arxiv.org/abs/2411.02618
Cite the original work for its findings. Save a collection to share your selection of sources.