Summary
A CVE is a globally unique ID for a single vulnerability, like a license plate, while CVSS supplies the zero-to-10 technical severity score and CNAs are the trusted organizations that assign CVE IDs. Landon Miles ties the vocabulary together around one point: a high CVSS score reflects technical severity, not business risk. Before you decide what to patch first, you layer in context. Is it internet exposed, is there a public proof of concept, is it being actively exploited, and what is the blast radius if it is.
)
)
)
)
)
)
)