How do you use CVSS responsibly when prioritizing?
Start with applicability and let policy determine the final order.
A useful order is:
- verify that the vulnerability applies to the product;
- check the CVSS base score and vector for that product;
- add current threat information and actual environmental factors;
- include additional context, such as safety, recoverability and legal obligations;
- apply your own policy for priority, treatment and risk acceptance;
- record the decision and substantiation.
This does not create an automatic repair list, but a decision that can be followed. FIRST recommends using Threat and Environmental Metrics for a more meaningful result and calls the outcome an input for your own vulnerability and risk handling.