How do you use CVSS responsibly when prioritizing?

Start with applicability and let policy determine the final order.

A useful order is:

  1. verify that the vulnerability applies to the product;
  2. check the CVSS base score and vector for that product;
  3. add current threat information and actual environmental factors;
  4. include additional context, such as safety, recoverability and legal obligations;
  5. apply your own policy for priority, treatment and risk acceptance;
  6. record the decision and substantiation.

This does not create an automatic repair list, but a decision that can be followed. FIRST recommends using Threat and Environmental Metrics for a more meaningful result and calls the outcome an input for your own vulnerability and risk handling.