{"guid":"937f25c1-8ce3-52bc-b647-d5db9ef64d57","title":"Don’t judge a vulnerability by its CVSS score","subtitle":null,"slug":"2025-204-don-t-judge-a-vulnerability-by-its-cvss-score","link":"https://pretalx.hackerhotel.nl/2025/talk/DHNUWQ/","description":"The total number of vulnerabilities continues to rise. If we had to rely on just CVSS for prioritizing those vulnerabilities, we have an enormous hard time to remediate all of them. In this talk, we’ll explore the critical gaps in CVSS-based prioritization and discuss why factors like exploitability, asset criticality, and real-time threat intelligence are way more important. Expect real-world examples, a touch of humor, and actionable insights to help you move beyond the CVSS score and toward a smarter, risk-based approach to vulnerability management.\n\nBecause let’s face it: a CVSS 7 can be way more critical to your organization then a CVSS 9!\n\nLicensed to the public under http://creativecommons.org/licenses/by/4.0","original_language":"eng","persons":["Stefan Lambregts"],"tags":["204","2025","hackerhotel2025","Talks","Leonardo Da Vinci","hackerhotel2025-eng","Day 2"],"view_count":287,"promoted":false,"date":"2025-02-15T14:30:00.000+01:00","release_date":"2025-02-15T00:00:00.000+01:00","updated_at":"2026-03-27T21:30:06.237+01:00","length":1652,"duration":1652,"thumb_url":"https://static.media.ccc.de/media/events/hackerhotel/2025/204-937f25c1-8ce3-52bc-b647-d5db9ef64d57.jpg","poster_url":"https://static.media.ccc.de/media/events/hackerhotel/2025/204-937f25c1-8ce3-52bc-b647-d5db9ef64d57_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/hackerhotel/2025/204-937f25c1-8ce3-52bc-b647-d5db9ef64d57.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/hackerhotel/2025/204-937f25c1-8ce3-52bc-b647-d5db9ef64d57.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/2025-204-don-t-judge-a-vulnerability-by-its-cvss-score","url":"https://api.media.ccc.de/public/events/937f25c1-8ce3-52bc-b647-d5db9ef64d57","conference_title":"HackerHotel 2025","conference_url":"https://api.media.ccc.de/public/conferences/hackerhotel2025","related":[],"recordings":[{"size":25,"length":1652,"mime_type":"audio/mpeg","language":"eng","filename":"hackerhotel2025-204-eng-Dont_judge_a_vulnerability_by_its_CVSS_score_mp3.mp3","state":"new","folder":"mp3","high_quality":false,"width":0,"height":0,"updated_at":"2025-02-15T22:43:39.276+01:00","recording_url":"https://cdn.media.ccc.de/events/hackerhotel/2025/mp3/hackerhotel2025-204-eng-Dont_judge_a_vulnerability_by_its_CVSS_score_mp3.mp3","url":"https://api.media.ccc.de/public/recordings/84832","event_url":"https://api.media.ccc.de/public/events/937f25c1-8ce3-52bc-b647-d5db9ef64d57","conference_url":"https://api.media.ccc.de/public/conferences/hackerhotel2025"},{"size":17,"length":1652,"mime_type":"audio/opus","language":"eng","filename":"hackerhotel2025-204-eng-Dont_judge_a_vulnerability_by_its_CVSS_score_opus.opus","state":"new","folder":"opus","high_quality":false,"width":0,"height":0,"updated_at":"2025-02-15T22:43:35.484+01:00","recording_url":"https://cdn.media.ccc.de/events/hackerhotel/2025/opus/hackerhotel2025-204-eng-Dont_judge_a_vulnerability_by_its_CVSS_score_opus.opus","url":"https://api.media.ccc.de/public/recordings/84831","event_url":"https://api.media.ccc.de/public/events/937f25c1-8ce3-52bc-b647-d5db9ef64d57","conference_url":"https://api.media.ccc.de/public/conferences/hackerhotel2025"},{"size":70,"length":1652,"mime_type":"video/webm","language":"eng","filename":"hackerhotel2025-204-eng-Dont_judge_a_vulnerability_by_its_CVSS_score_webm-sd.webm","state":"new","folder":"webm-sd","high_quality":false,"width":720,"height":576,"updated_at":"2025-02-22T10:28:52.985+01:00","recording_url":"https://cdn.media.ccc.de/events/hackerhotel/2025/webm-sd/hackerhotel2025-204-eng-Dont_judge_a_vulnerability_by_its_CVSS_score_webm-sd.webm","url":"https://api.media.ccc.de/public/recordings/84870","event_url":"https://api.media.ccc.de/public/events/937f25c1-8ce3-52bc-b647-d5db9ef64d57","conference_url":"https://api.media.ccc.de/public/conferences/hackerhotel2025"},{"size":225,"length":1652,"mime_type":"video/webm","language":"eng","filename":"hackerhotel2025-204-eng-Dont_judge_a_vulnerability_by_its_CVSS_score_webm-hd.webm","state":"new","folder":"webm-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2025-02-22T11:11:41.532+01:00","recording_url":"https://cdn.media.ccc.de/events/hackerhotel/2025/webm-hd/hackerhotel2025-204-eng-Dont_judge_a_vulnerability_by_its_CVSS_score_webm-hd.webm","url":"https://api.media.ccc.de/public/recordings/84860","event_url":"https://api.media.ccc.de/public/events/937f25c1-8ce3-52bc-b647-d5db9ef64d57","conference_url":"https://api.media.ccc.de/public/conferences/hackerhotel2025"},{"size":64,"length":1652,"mime_type":"video/mp4","language":"eng","filename":"hackerhotel2025-204-eng-Dont_judge_a_vulnerability_by_its_CVSS_score_sd.mp4","state":"new","folder":"h264-sd","high_quality":false,"width":720,"height":576,"updated_at":"2025-02-22T09:29:44.949+01:00","recording_url":"https://cdn.media.ccc.de/events/hackerhotel/2025/h264-sd/hackerhotel2025-204-eng-Dont_judge_a_vulnerability_by_its_CVSS_score_sd.mp4","url":"https://api.media.ccc.de/public/recordings/84830","event_url":"https://api.media.ccc.de/public/events/937f25c1-8ce3-52bc-b647-d5db9ef64d57","conference_url":"https://api.media.ccc.de/public/conferences/hackerhotel2025"},{"size":310,"length":1652,"mime_type":"video/mp4","language":"eng","filename":"hackerhotel2025-204-eng-Dont_judge_a_vulnerability_by_its_CVSS_score_hd.mp4","state":"new","folder":"h264-hd","high_quality":true,"width":1920,"height":1080,"updated_at":"2025-02-21T23:34:54.104+01:00","recording_url":"https://cdn.media.ccc.de/events/hackerhotel/2025/h264-hd/hackerhotel2025-204-eng-Dont_judge_a_vulnerability_by_its_CVSS_score_hd.mp4","url":"https://api.media.ccc.de/public/recordings/84812","event_url":"https://api.media.ccc.de/public/events/937f25c1-8ce3-52bc-b647-d5db9ef64d57","conference_url":"https://api.media.ccc.de/public/conferences/hackerhotel2025"}]}