Misconception M4 / F2

CVSS alone is not the patch order

CVSS alone is the patch order.

Wrong claim

Why it feels true

Two scanner rows with the same high number look like a fair queue, and the higher number looks more urgent.

Precise correction

The FIRST CVSS v4.0 user guide states that the CVSS Base score measures severity, not risk, and should not be used alone to assess risk.

Riverstone still puts exposure, the asset that would fail, and exploitation signals such as CISA’s Known Exploited Vulnerabilities catalog and FIRST’s Exploit Prediction Scoring System in their own columns.

The internet-facing VPN and the internal lunch-menu wiki can share a high score and still deserve different nights.

FIRST CVSS v4.0 User Guide: CVSS-B measures severity, not risk ↗

MINI-CHECK

The scanner marks both the internet VPN and the office wiki plugin “critical,” with similar CVSS scores. The VPN is on CISA’s Known Exploited Vulnerabilities catalog. Devon wants the wiki first because it is easier. What should Maya record?

Go deeper

Find your next idea.

Tip: press / to open search. Escape closes this window.