ART OF VECTOR

CVE to Real Risk

A CVE number is not a risk score.

Rank a published record the way an incident owner should: do we run it, can it be reached, is authentication required, and is it known to be exploited? CISA KEV is one input.
  1. → CVE
  2. ↓ Affected versions
  3. ↓ Exposure
  4. ↓ Reachability
  5. ↓ Authentication required?
  6. ↓ Network reachable?
  7. ↓ Exploitability
  8. ↓ Impact
  9. ↓ Known exploitation?

This program does not publish exploit code to “prove” severity. Urgency and impact class stay in separate columns. A KEV item can be urgent and still not be RCE.

Notes

FAQ

Questions

What is CISA KEV used for here?
The Known Exploited Vulnerabilities catalog is one input for known exploitation. It sets urgency. It does not automatically mean the impact class is RCE.