skip to content

What does an EPSS score of 0.08 on a CVE actually tell you about that vulnerability?

level: juniorimportance: must knowfreq 62%

answer

  1. It is a forecast, not a rating
  2. A number between zero and one
  3. Thirty-day window, recalculated daily
  4. Says nothing about impact or your network
  5. Keyed to CVE ids only

basics

~10 s

EPSS estimates the probability a vulnerability will be exploited in the wild within 30 days. A score of 0.08 means roughly an 8 percent chance. It forecasts likelihood, not how damaging the flaw is.

solid answer

~40 s

EPSS, the Exploit Prediction Scoring System published by FIRST, is a model that outputs a number between 0 and 1 for a CVE: the estimated probability that exploitation activity will be observed in the wild within the next 30 days. So 0.08 is roughly an 8 percent chance, recalculated daily as the model's inputs change. Crucially it is a statement about the vulnerability in the world, not about me: it knows nothing about my network, my compensating controls, or whether my code even calls the vulnerable function. It also says nothing about impact - that is what a severity rating covers. In triage I use EPSS to order a queue, never to close a finding, and I remember that a finding without a CVE ID has no EPSS score at all.

go deeper

for a junior

Be ready to say in one sentence that EPSS is a probability of exploitation in the wild over the next 30 days, and that it is separate from how severe the flaw is.

for a middle

Explain that scores are recalculated daily, are keyed to CVE ids, and are blind to your environment - so EPSS orders a queue but never justifies closing an item.

for a senior

Show how EPSS sits beside applicability, reachability and severity in a triage decision, and how you handle findings with no score rather than letting them fall out of the queue.

for a principal

Own the argument for why a likelihood signal belongs in the programme at all: it is what lets you defend a work order to an auditor or an executive who only sees severity bands.

## What EPSS is EPSS - the Exploit Prediction Scoring System, published by FIRST - is a statistical model that answers one narrow question about a CVE: **how likely is it that exploitation of this flaw will be observed in the wild in the next 30 days?** The output is a probability between 0 and 1, published alongside a percentile that shows where that probability ranks among all scored CVEs. Scores are regenerated daily, so the number attached to a finding today is not necessarily the number it had last week. ## Reading 0.08 A score of 0.08 means the model puts roughly an 8-in-100 chance on exploitation activity being seen somewhere in the world during the next month. It is a **population-level forecast about the vulnerability**, not a measurement of your estate. ## What EPSS is not - **Not a severity rating.** Severity describes the flaw's intrinsic characteristics - how it is reached, what privileges an attacker needs, what breaks if it works. EPSS says nothing about damage. A flaw that destroys a database and a flaw that leaks a version banner can carry the same EPSS score. - **Not exposure or reachability.** The model's inputs are properties of the vulnerability and of public activity around it - published exploit code, references, observed attack traffic. None of that is your firewall, your architecture, or whether the vulnerable function is on a code path you actually execute. - **Not evidence.** EPSS predicts. A known-exploited catalog records what has already been observed. A low EPSS and a catalog entry can coexist for a short window, and the observed fact wins. - **Not a licence to close.** A near-zero score means broad opportunistic exploitation is unlikely, not that nobody can exploit it against you. An attacker who is specifically targeting your organisation is not the population this model was trained on. ## Units matter Do not compare an EPSS score numerically to a severity score. 0.08 and 7.5 are answers to different questions in different units: one is a probability of attack activity, the other a rating of the flaw's intrinsic seriousness. Candidates who say "EPSS 0.08 so it is low severity" have merged the two, and that is the single most common wrong answer here. ## Coverage gaps you must plan for EPSS is keyed to **CVE identifiers**. An ecosystem advisory published without a CVE ID will have no EPSS score. A very freshly published CVE may sit unscored briefly. Any triage policy that cuts a queue on EPSS therefore needs a defined default lane for unscored findings, or those findings quietly vanish - which is exactly the sort of silent gap an interviewer will probe. ## Where it belongs in triage A finding is worth working on for several independent reasons, and EPSS supplies exactly one of them: | Question | What answers it | |---|---| | Does this even apply to my version? | The advisory's affected range | | Can the vulnerable code be reached? | Reachability analysis | | How bad if it works? | Severity rating | | How likely is anyone to try? | **EPSS** | | Is it already being used? | A known-exploited catalog | The unique contribution of EPSS is the likelihood column - nothing else on the row gives you that. It is a sorting key, not a verdict. ## Volatility Because scores are recalculated daily, an item can cross a threshold in either direction after it has been raised. Decide deliberately whether a re-score can promote a finding, demote one, or neither, and write it down. Teams that leave this implicit end up with a queue that reshuffles itself overnight and nobody trusting the order.

  • If a CVE's EPSS score is near zero, can you close the finding?
    No. A near-zero score says broad exploitation activity is unlikely across the population of attackers, not that the flaw is unreachable or harmless in your system. It is also blind to a targeted attacker who cares specifically about you. Use it to decide what to work on first, not what to stop working on; closing needs a reason drawn from your own environment.
  • Which findings in your queue will have no EPSS score at all?
    EPSS is keyed to CVE identifiers, so anything advised without one - some ecosystem-only advisories - has no score, and a very fresh CVE may be unscored for a short period. If your triage cut is written purely as a numeric threshold, those findings fall through the floor. Give unscored items an explicit default lane, usually manual review rather than automatic deprioritisation.
  • Why is comparing an EPSS score to a severity score directly a mistake?
    They are different units answering different questions. Severity rates the intrinsic seriousness of the flaw - how it is reached and what it damages. EPSS estimates the probability of exploitation activity being observed. A flaw can be devastating and rarely attacked, or trivial and constantly probed. You need both numbers side by side, not one converted into the other.

A weather forecast gives the chance of rain tomorrow; it does not tell you how much damage a flood would do to your particular house, or whether your roof leaks. EPSS is the chance of rain.

saying these in an interview costs you the question

  • Calls EPSS a severity rating or a criticality band
  • Says EPSS accounts for the organisation's network exposure
  • Closes findings because the EPSS score is low
  • Thinks EPSS predicts exploitation of their systems specifically
  • Assumes every advisory carries an EPSS score

context