0
My CVE triage process was backwards for 2 years until a pentest report smacked me
I used to rank vulnerabilities by CVSS score alone, thought that was the whole job. Last month our pentester found a medium severity SSRF that let him hit our internal metadata endpoint in AWS, full creds in 20 minutes. That high severity SQLi I kept patching first? It was behind a WAF and basically useless to an attacker. The report literally said 'your scoring is fine, your business context is missing.' Now I map every finding to what data it touches and what systems it can pivot to, not just the number. Anyone else still triaging purely off CVSS and feeling exposed?
0 comments
Log in to join the discussion
Log In0 Comments
No comments yet
Be the first to share your thoughts on this discussion.