Back to blogTechnical Security

Vulnerability Management: From CVSS to a Remediation Plan

Aranis· Plataforma de inteligência de risco
July 6, 20266 min read

Vulnerability management is the ongoing process of identifying, classifying, prioritizing, and fixing security flaws before someone exploits them. CVSS (Common Vulnerability Scoring System) is the international standard for severity scoring — but treating it as the only source of truth is the most common mistake in immature programs.

How CVSS v3.1 works

Scores range from 0 to 10: None (0), Low (0.1–3.9), Medium (4.0–6.9), High (7.0–8.9), Critical (9.0–10.0), combining Base, Temporal, and Environmental metrics. It's a good starting point — but only that.

Why CVSS alone isn't enough

The base score doesn't account for whether a vulnerability is being actively exploited, how exposed the affected asset actually is, or its real criticality to the business. That's where EPSS (Exploit Prediction Scoring System) comes in: it estimates the real probability of exploitation in the next 30 days, based on observed data — not theory.

Remediation SLAs that actually make sense

Critical with confirmed active exploitation (listed in the CISA KEV catalog) demands remediation in 24-72h. High on a business-critical asset, 7 days. High on a standard asset, 30 days. Medium and Low fall into the normal patch management cycle, typically 90 days. Fixed SLAs without this exploitation-and-criticality context create either unnecessary panic or dangerous complacency.

From an isolated score to context-driven prioritization

A mature program combines three layers: technical severity (CVSS), real exploitation likelihood (EPSS + threat intel like CISA KEV), and business criticality of the asset. That combination is what the Aranis platform takes into account when prioritizing vendor vulnerabilities — considering what each asset means to the business, so your team prioritizes what actually matters instead of chasing a list sorted by CVSS alone.

A Critical vulnerability on an isolated system with no sensitive data may matter less than a Medium one on an internet-facing system with access to customer data.

vulnerability managementCVSSEPSSpatch management