1. Knowledge Base
  2. Risk Based Vulnerability Management

How do I use the prediction score?

The Orpheus score should be used to prioritize vulnerability patching, with exploited vulnerabilities with the highest score patched first, followed by currently exploited vulnerabilities with a low score then highly likely future exploits.

The prediction score can be used to help you prioritize your vulnerability patching schedule. We recommend that organizations patch exploited vulnerabilities with the highest Orpheus score first. We then suggest that you patch vulnerabilities that are currently exploited and have a low Orpheus score. We would then suggest patching vulnerabilities that are highly likely to be exploited in the future.

This differs from some industry advice that advises patching based on the CVSS severity score, not taking into account whether vulnerabilities have been exploited, or are likely to be exploited in the future.