-
* related to #4473
EPSS tests are surprisingly hard because the scores change constantly, and we had to disable some of the tests originally written because they were too unstable. But as a resu…
-
### Current Behavior
Got vulnerabilities sourced from GitHub Advisories and the severities are listed on "Audit Vulnerabilites" tab
![Image](https://github.com/user-attachments/assets/14519c6d-e9f0-…
-
**Is your feature request related to a problem?**
Managing vulnerabilities by severity is cumbersome and in many cases an impossible problem. There's a need to also have an Exploitation Predictibilit…
-
In the course of debugging #4083 I'm seeing mostly timeouts for EPSS and I'm not sure it's working for me. Is it actually working for anyone else at the moment, or did I break it while making it poss…
-
What would you like to be added:
for each CVE provide also the epss score based on this - https://www.first.org/epss/
Why is this needed:
calculate better the risk for each CVE
Additional context:…
-
We would like the optional inclusion of the EPSS score of a vulnerability in the `scores` section within the `vulnerability properties` of a CSAF document.
-
|Wazuh version|Component|
|---|---|
| 4.3.10 | Wazuh integration |
## Description
Vulnerability management capabilities include CVE and treats all findings as almost the same based on severity…
-
I'd like to add EPSS (https://www.first.org/epss/) to the severity field, which is a form of severity (how likely is it going to be exploited).
One wrinkle: EPSS scores include:
epss : the EPSS …
-
## Describe the feature
Vulnerabilities can have an [EPSS](https://www.first.org/epss/) score attached to them. This describes the probability of a vulnerability being exploited. As of spec version…
-
Discuss with Alvaro, slide "Integration of EPSS"...
After PoC done internally, we could integrate this here?