Conflicting Scores, Confusing Signals: An Empirical Study of Vulnerability Scoring Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Koscinski, Viktoria, Nelson, Mark, Okutan, Ahmet, Falso, Robert, Mirakhorli, Mehdi
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909743081062400
author Koscinski, Viktoria
Nelson, Mark
Okutan, Ahmet
Falso, Robert
Mirakhorli, Mehdi
author_facet Koscinski, Viktoria
Nelson, Mark
Okutan, Ahmet
Falso, Robert
Mirakhorli, Mehdi
contents Accurately assessing software vulnerabilities is essential for effective prioritization and remediation. While various scoring systems exist to support this task, their differing goals, methodologies and outputs often lead to inconsistent prioritization decisions. This work provides the first large-scale, outcome-linked empirical comparison of four publicly available vulnerability scoring systems: the Common Vulnerability Scoring System (CVSS), the Stakeholder-Specific Vulnerability Categorization (SSVC), the Exploit Prediction Scoring System (EPSS), and the Exploitability Index. We use a dataset of 600 real-world vulnerabilities derived from four months of Microsoft's Patch Tuesday disclosures to investigate the relationships between these scores, evaluate how they support vulnerability management task, how these scores categorize vulnerabilities across triage tiers, and assess their ability to capture the real-world exploitation risk. Our findings reveal significant disparities in how scoring systems rank the same vulnerabilities, with implications for organizations relying on these metrics to make data-driven, risk-based decisions. We provide insights into the alignment and divergence of these systems, highlighting the need for more transparent and consistent exploitability, risk, and severity assessments.
format Preprint
id arxiv_https___arxiv_org_abs_2508_13644
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Conflicting Scores, Confusing Signals: An Empirical Study of Vulnerability Scoring Systems
Koscinski, Viktoria
Nelson, Mark
Okutan, Ahmet
Falso, Robert
Mirakhorli, Mehdi
Cryptography and Security
Software Engineering
Accurately assessing software vulnerabilities is essential for effective prioritization and remediation. While various scoring systems exist to support this task, their differing goals, methodologies and outputs often lead to inconsistent prioritization decisions. This work provides the first large-scale, outcome-linked empirical comparison of four publicly available vulnerability scoring systems: the Common Vulnerability Scoring System (CVSS), the Stakeholder-Specific Vulnerability Categorization (SSVC), the Exploit Prediction Scoring System (EPSS), and the Exploitability Index. We use a dataset of 600 real-world vulnerabilities derived from four months of Microsoft's Patch Tuesday disclosures to investigate the relationships between these scores, evaluate how they support vulnerability management task, how these scores categorize vulnerabilities across triage tiers, and assess their ability to capture the real-world exploitation risk. Our findings reveal significant disparities in how scoring systems rank the same vulnerabilities, with implications for organizations relying on these metrics to make data-driven, risk-based decisions. We provide insights into the alignment and divergence of these systems, highlighting the need for more transparent and consistent exploitability, risk, and severity assessments.
title Conflicting Scores, Confusing Signals: An Empirical Study of Vulnerability Scoring Systems
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2508.13644