Skip to content

Writing

Severity is not priority, and treating it as one is why nobody uses your scanner

A CVSS score is computed without knowing whether the code is reachable, what the system holds, or who can get to it. Sorting by it produces a list that is wrong at the top.

A scanner rates a finding High because the class of bug is dangerous. It does not know whether the vulnerable function is ever called, whether the system is on the internet, whether it holds anything, or whether an attacker would need credentials nobody outside the building has.

Those four facts change the answer completely, and every one of them is knowable. Two identical library vulnerabilities — one in a code path reached by an unauthenticated request to a system holding customer records, one in a build script — are not the same problem, and a list that puts them adjacent has wasted the reader’s afternoon.

What we score on instead

Reachability first: is the vulnerable code actually called from an entry point? When we cannot tell, we say we cannot tell, rather than assuming the worse case and quietly inflating everything.

Then exposure, then what the system holds — which comes from what you recorded about the target rather than from a guess about your business. Then how long it has been open, because an old finding is a decision somebody keeps making.

The output is an order, and each finding shows the factors that put it where it is. A ranking you cannot interrogate is a ranking nobody trusts twice.

The test of a good queue

Not "did we find more" — anybody can find more by turning down the threshold. The test is whether somebody who works down the list from the top spends their day on the right things, and whether the bottom of the list can be safely ignored.

That second half is the one nobody builds for, and it is the one that decides whether the tool gets opened in week three.