Rewriting the Playbook: Smarter Vulnerability Management with EPSSv3, CVSSv4, SSVC & VEX Frameworks

Avinash Nutalapati

BSides Las Vegas 2025 · Day 1

Overview

Avin delivers an introductory-to-intermediate talk aimed at vulnerability management leaders who feel buried in CVE noise. The speaker, who identifies as a vulnerability analyst at Discover working in an application security team while the organization also maintains separate infrastructure vulnerability management, walks through four public frameworks—CVSSv4, EPSS (with emphasis on EPSSv4), VEX, and SSVC—and proposes a phased integration model spanning months for a mid-sized enterprise (~5,000–10,000 employees in the speaker’s example). A strong disclaimer anchors the session: the frameworks are public and the talk is not a description of Discover’s internal implementation strategy or undisclosed operational details.

Watch on YouTube

Visual summary for Rewriting the Playbook: Smarter Vulnerability Management with EPSSv3, CVSSv4, SSVC & VEX Frameworks by Avinash Nutalapati
Visual summary for Rewriting the Playbook: Smarter Vulnerability Management with EPSSv3, CVSSv4, SSVC & VEX Frameworks by Avinash Nutalapati

Key moments

  1. 2:00 Disclaimer: public frameworks only; not Discover’s undisclosed VM strategy.
  2. 4:00 CVSSv3 pain points: severity in isolation, environmental gaps, exploitability over time.
  3. 6:00 CVSSv4 additions and NVD timeline notes; mixed v3/v4 reporter strings.
  4. 8:00 EPSS as 30-day exploitation prediction; insist on EPSSv4 data; percentile prioritization.
  5. 10:00 VEX outcomes vs runtime call-flow analysis; SBOM vendor ask for financial sector.
  6. 12:00 SSVC track/track/attend/act; customize CISA tree for finance vs healthcare factors.
  7. 14:00 Proposed pipeline: centralize findings, enrich CVSS+EPSS+KEV, VEX filter, SSVC SLAs.
  8. 18:00 Phased rollout timeline (months), automation targets, audit alignment on risk rating.

Rewriting the Playbook: Smarter Vulnerability Management with EPSSv3, CVSSv4, SSVC & VEX Frameworks

Speakers: Avin (Vulnerability Analyst, Discover; transcript: “Avin”; full name spelling not confirmed), Application Security context described

Conference: BSides Las Vegas

YouTube: https://www.youtube.com/watch?v=pvRFP3aht7g

Overview

Avin delivers an introductory-to-intermediate talk aimed at vulnerability management leaders who feel buried in CVE noise. The speaker, who identifies as a vulnerability analyst at Discover working in an application security team while the organization also maintains separate infrastructure vulnerability management, walks through four public frameworks—CVSSv4, EPSS (with emphasis on EPSSv4), VEX, and SSVC—and proposes a phased integration model spanning months for a mid-sized enterprise (~5,000–10,000 employees in the speaker’s example). A strong disclaimer anchors the session: the frameworks are public and the talk is not a description of Discover’s internal implementation strategy or undisclosed operational details.

The motivation is operational: CVSSv3-heavy programs generate too many “critical” findings, weak threat context, environmental irrelevance, and time-varying exploitability that static scores fail to capture. The speaker repeatedly distinguishes tool severity from organizational risk, arguing security teams need a defensible way to translate scanner output into SLAs, executive reporting, and audit conversations—especially under heightened regulatory attention ( PCI DSS mentioned as an example driver).

Background

▶ Watch: Disclaimer: public frameworks only; not Discover’s undisclosed VM strategy. (2:00)

Why CVSSv3 falls short (as framed in the talk)

The speaker lists recurring limitations: severity in isolation (a vulnerability may be exploitable in a lab but not in a hardened corporate environment), missing environmental nuance, and mixed exploitability signals—exploit code may appear years after CVE publication. The talk also highlights vulnerability chaining: attackers rarely rely on a single flaw, so prioritizing solely by single-CVE scores can misallocate effort. A conceptual point is repeated: theoretical maximum impact is not equal to observed exploitation.

CVSSv4: what changes

CVSSv4 is presented as addressing “too many criticals,” lack of threat context, and insufficient flexibility when exploitation modes differ (automatic vs manual). New dimensions mentioned include attack requirements, refined user interaction (including passive vs active notions in the speaker’s wording), and impact on subsequent systems (transitive impact beyond the vulnerable component). NVD adoption is discussed at a high level: CVSSv4 appears in NVD workflows from June 2024 (per the talk), analysts are migrating, and there is a stated NVD plan to convert legacy v3 vectors to v4 by end of year—with the speaker expressing uncertainty about feasibility on that timeline. Vendor submissions may still arrive as v3 strings depending on reporters, so pipelines should tolerate mixed versions during transition.

EPSS: probabilistic prioritization

EPSS is described as a machine learning model estimating the probability a vulnerability will be exploited in the next 30 days, using vendor/CVE history and related signals. EPSS percentiles accompany scores to rank CVEs relative to the population. The speaker’s prescriptive sound bite: prioritize work toward high percentiles when triaging at scale. A critical housekeeping note is repeated: ensure tools ingest EPSSv4 data if claiming EPSS support—v3 allegedly clustered too many findings at high scores, while v4 spreads distributions more usefully (the session references a comparative diagram).

VEX: triage outcomes for SBOM world

VEX is framed as manual triage attached to components, often alongside SBOM workflows: analysts determine whether a vulnerable component is reachable/used. Four outcomes are listed: not affected, affected, fixed, and under investigation. The speaker distinguishes VEX from call flow analysis: call flow is runtime automatic analysis, while VEX is characterized as manual analyst judgment (with automation potential “for now” limited in practice).

A vendor-management callout targets financial and broader enterprises: request SBOMs from vendors because “we are not impacted” does not imply vendors are clean—third-party risk remains.

SSVC: qualitative decision outcomes

SSVC is described as a qualitative method (no numeric score) with four end states: track, track with an asterisk (the speaker verbally describes “track with a star” as a heightened tracking state), attend, and act—where act is highest urgency. The speaker attributes origins to Carnegie Mellon research adapted by CISA. The default CISA decision tree is said to be a poor fit for financial industry nuance; organizations should customize trees using factors like internal vs external exposure, PCI impact, and data classification. Mission and well-being factors are called out as healthcare-aligned and not universally applicable.

Key Findings

▶ Watch: CVSSv4 additions and NVD timeline notes; mixed v3/v4 reporter strings. (6:00)

The speaker proposes treating frameworks as filters in series:

  1. Centralize findings (vendor ASPM platforms, in-house pipelines, or even Excel—anything, as long as it is single-pane) with CVE, component identity, and asset context.
  2. Enrich with CVSS (prefer v4 when available), EPSS scores/percentiles, and CISA KEV status (boolean mentioned), refreshed daily where applicable.
  3. Apply VEX-like triage (possibly overlapping vendor eBPF / call-flow tooling) to mark not affected and drop noise.
  4. Route remaining high-criticality items through SSVC for act/attend/track decisions and attach SLAs (examples: 15-day or 30-day for act outcomes).

Quick wins highlighted: integrate EPSS and KEV, start an SBOM pilot on one or two systems, and wire CVSSv4 fields as NVD populates them.

Heavier lifts (example timeline): 5–6 months for deeper VEX integration and code reachability team processes; SSVC last due to training and customization needs, with pilot then full rollout.

Technical Deep Dive

▶ Watch: VEX outcomes vs runtime call-flow analysis; SBOM vendor ask for financial sec... (10:00)

SSVC decision tree literacy

Using the CISA tree as a teaching example, the speaker notes only a handful of paths lead to act, typically involving active exploitation and automatable attack characteristics combined with meaningful technical impact distinctions. The talk encourages teams to read the official tree, then rebuild branches aligned to their control environment—e.g., demote issues on internal-only systems with strong network segmentation.

VEX and runtime analysis overlap

The speaker acknowledges eBPF-based and other runtime reachability products as partially overlapping VEX but not equivalent: reachability can accelerate triage, yet policy outcomes still need human ownership for exceptions and compensating controls.

EPSS integration mechanics

FIRST.org is cited as the home for EPSS and CVSS resources with an API for ingestion into pipelines—useful for teams building internal enrichment rather than buying a aggregator.

DAST findings without CVEs

In Q&A, the speaker states SSVC may help prioritize non-CVE DAST findings (e.g., SQL injection) using environmental context, while VEX is less natural without SBOM anchoring unless customized.

Measuring success

Another question probes metrics for proving the new methodology beats the old. The speaker answers with human resources (skilled analysts who read CVE text and map to environment) and technology (automation quality). This is honest: the frameworks do not remove labor; they reallocate it toward higher-leverage decisions.

Demo / Proof of Concept

▶ Watch: SSVC track/track*/attend/act; customize CISA tree for finance vs healthcare f... (12:00)

The session is primarily slide-driven methodology rather than a live tool demo. The speaker offers to share example executive reporting slides on LinkedIn pending company approval—details of those visuals are not reproducible from the transcript alone.

Defensive Implications

▶ Watch: Phased rollout timeline (months), automation targets, audit alignment on risk... (18:00)

  • Build an enrichment pipeline before arguing about scoring philosophy—without KEV, EPSS, and CVSSv4 fields, debates lack shared data.
  • Treat tool criticality as input, not verdict; publish an internal risk rating methodology so audit and engineering align.
  • Start SBOM pilots where component inventory is tractable; use them to accelerate VEX outcomes.
  • Invest in training across AppSec, infra VM, threat intel, and audit partners—methodology changes fail when only scanners update.
  • Automate the boring parts: KEV tagging, EPSS scoring, SBOM generation, ticket creation—Excel is acceptable to start, but becomes a liability at scale.

Operationally, the talk implies ticket hygiene is part of the control: if SSVC says act but your ITSM still routes solely by scanner severity, you have two competing systems of record. The speaker’s SLA examples (15 vs 30 days) are not universal standards—treat them as illustrations and derive numbers from business impact, regulatory clocks, and threat intel cadence.

For PCI-regulated environments, the session’s mention of vulnerability scrutiny is a reminder to connect VM policy to compensating controls documentation: when you downgrade work using VEX or environmental context, ensure evidence is reviewable (reachability proof, config screenshots, WAF rules) rather than “analyst gut feel” captured only in a comment field.

Finally, treat framework adoption as change management: update policy, standards, and exception processes in the same quarter you flip enrichment bits—otherwise teams will revert to raw CVSS when incidents strike and adrenaline overrides methodology.

That discipline is what turns an acronym stack into durable risk reduction.

Key Takeaways

  • CVSSv3-only programs overweight theoretical severity; CVSSv4 adds dimensions closer to exploit physics, but migration will be patchy during NVD transition.
  • EPSS (ensure v4 data) helps rank “will this burn next month” questions distinct from “how bad if it burns.”
  • VEX supplies standardized triage outcomes for component-level exposure, especially alongside SBOMs.
  • SSVC converts complex situations into action policies—if you adopt CISA’s tree wholesale in finance, expect misfit; customize.
  • Successful rollouts are sequenced and cross-functional; the hardest part is not the acronym soup but operational integration and governance alignment.

About the Speaker(s)

Avin introduces himself as a vulnerability analyst at Discover on an application security team, presenting publicly for the first time by his own remark. He emphasizes the talk reflects public frameworks, not Discover’s private strategy, and declines to disclose operational details about vendor SBOM collection at Discover. Any additional biographical details beyond the transcript are unknown.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent VM enablement talk: a readable map of CVSSv4/EPSS/VEX/SSVC and a sensible phased adoption path. Light on novel research, but exactly the consolidation many practitioners need—if they verify NVD/EPSS migration details independently.

Heather Calloway (CISO) — STRONG ACCEPT

This is governance-ready material: it connects scanner outputs to audit pressure, vendor SBOM requests, and a staged methodology so risk ratings are explainable. The explicit separation between tool severity and organizational risk is the line every CISO needs repeated.

→ Top-rated talks at BSides Las Vegas 2025

All talks from BSides Las Vegas 2025