Exploit Maturity: Your New Best Friend in CVSS
Shelby Cunningham (GitHub)
CVE/FIRST VulnCon 2025 · Main Stage
Overview
In her VulnCon talk, "Exploit Maturity: Your New Best Friend in CVSS," Shelby Cunningham, a member of GitHub's advisory database curation team and a CNA (Common Vulnerabilities and Exposures Numbering Authority), delves into the critical role of the Exploit Maturity (E) metric in the new CVSS 4.0 framework. Cunningham argues that this specific metric is an invaluable tool for vulnerability managers, maintainers, and consumers alike, addressing key challenges posed by the transition from CVSS 3.1 to 4.0.

Key moments
- 0:00 Talk introduction and agenda overview
- 1:05 Speaker's experience with CVSS scoring
- 4:39 Defining Exploit Maturity (E) in CVSS 4.0
- 5:53 Explaining the three maturity levels: Attacked, PoC, Unreported
- 7:00 The problem of vulnerability overscoring in CVSS 4.0
- 8:00 Data showing CVSS 4.0 scores higher than 3.1
Exploit Maturity: Your New Best Friend in CVSS
Speakers: Shelby Cunningham
Conference: VulnCon
YouTube: https://www.youtube.com/watch?v=n-V0TWBIzQQ
Overview
In her VulnCon talk, "Exploit Maturity: Your New Best Friend in CVSS," Shelby Cunningham, a member of GitHub's advisory database curation team and a CNA (Common Vulnerabilities and Exposures Numbering Authority), delves into the critical role of the Exploit Maturity (E) metric in the new CVSS 4.0 framework. Cunningham argues that this specific metric is an invaluable tool for vulnerability managers, maintainers, and consumers alike, addressing key challenges posed by the transition from CVSS 3.1 to 4.0.
The core problem Cunningham identifies is the tendency for CVSS 4.0 to assign higher scores to vulnerabilities compared to its predecessor, often leading to "overscoring" and potential alert fatigue. Exploit Maturity offers a sophisticated mechanism to temper these scores based on the actual likelihood and evidence of exploitation in the wild. Conversely, it also provides a direct, unambiguous way to flag vulnerabilities that are actively being exploited, ensuring they receive the urgent attention they warrant without relying solely on external intelligence feeds.
This talk is particularly pertinent for anyone involved in vulnerability management, security operations, or software development who grapples with the practical implications of CVSS scoring. Cunningham's insights, drawn from her extensive experience curating CVE records and assigning CVSS scores, highlight how E can improve the accuracy and actionability of vulnerability assessments, fostering better communication about true risk levels between vulnerability reporters, maintainers, and end-users.
Background
▶ Watch: Talk introduction and agenda overview (0:00)
The transition from CVSS 3.1 to CVSS 4.0 has introduced several significant changes, one of the most discussed being the potential for higher base scores for similar vulnerabilities. This phenomenon, often referred to as "overscoring," has raised concerns among organizations that rely on CVSS scores to prioritize remediation efforts. When a larger proportion of vulnerabilities are categorized as "critical" or "high" severity simply due to a scoring system update, it can lead to alert fatigue, where security teams become overwhelmed by a deluge of high-priority alerts, potentially diluting the urgency of truly critical threats.
Shelby Cunningham references a specific post by Aurora Sterita on mend.io, titled "CVSS3.1 versus CVSS4.0 and look at the data," which highlights this issue. This analysis found that CVSS 4.0 scores tended to be nearly 0.8 points higher on average across customer alerts. This seemingly small increase translated into substantial practical impacts: a 27% increase in critical severity alerts and an 18% increase in high severity alerts. Such shifts can force organizations to re-evaluate their entire vulnerability management policies and response strategies, as more vulnerabilities cross their established thresholds for immediate action.
Within this context, CVSS 4.0 introduces the Exploit Maturity (E) metric, a crucial component designed to add nuance to vulnerability assessment. Unlike the Exploit Code Maturity metric in CVSS 3.1, which had a different impact and scope, CVSS 4.0's Exploit Maturity is part of the "threat metrics" category. It measures the likelihood of a vulnerability being attacked, based on the current state of exploit techniques, the availability of exploit code, or active exploitation in the wild. This metric allows for a dynamic adjustment of the overall CVSS score, reflecting the real-world threat landscape rather than just the inherent technical characteristics of the vulnerability. Its introduction provides a mechanism to either temper potentially inflated base scores or to explicitly highlight severe, actively exploited vulnerabilities.
Key Findings
▶ Watch: Defining Exploit Maturity (E) in CVSS 4.0 (4:39)
Shelby Cunningham's talk primarily articulates two key findings regarding the practical application of the Exploit Maturity (E) metric in CVSS 4.0:
- Correcting Vulnerability Overscoring in CVSS 4.0: One of the most significant benefits of Exploit Maturity is its ability to mitigate the perceived overscoring issue in CVSS 4.0 compared to CVSS 3.1. Cunningham demonstrates how, by adjusting the Exploit Maturity value, vulnerability scores can be brought closer to what stakeholders might expect based on previous CVSS versions.
- For instance, a typical authenticated denial-of-service (DoS) attack with low privileges and low complexity would score 6.5 (Medium) in CVSS 3.1. In CVSS 4.0, with default threat metrics (assuming an "Attacked" state for Exploit Maturity), this same vulnerability could jump to 7.1 (High). However, if there's no evidence of in-the-wild exploitation, setting Exploit Maturity to Proof of Concept (P) brings the score down to 5.7 (Medium), or even 4.9 (Medium) if it's Unreported (U). These adjusted scores are much closer to the CVSS 3.1 expectation, preventing unnecessary alert escalation.
- Another example, an information disclosure vulnerability with high complexity (CVSS 3.1) scoring 6.8 (Medium), could soar to 8.2 (High) in CVSS 4.0. By applying Exploit Maturity, this can be reduced to 6.9 (High-Medium) with a Proof of Concept, or a more moderate 4.6 (Medium) if it remains Unreported. This flexibility allows CNAs and maintainers to provide a more accurate and less alarmist assessment when real-world exploitation is not confirmed.
- Improving Records by Including Exploit Status Information Directly: Exploit Maturity offers a direct and integrated way to signal the real-world exploitation status of a vulnerability within the CVSS string itself. This eliminates the need for consumers to consult external databases like the CISA Known Exploited Vulnerabilities (KEV) catalog or Exploit Prediction Scoring System (EPSS) for initial risk assessment.
- Cunningham cites a specific case (CVE 2023-39363) where a maintainer was concerned that the CVSS 3.1 score of 6.5 (Medium), even when adjusted to 8.7 (High) for availability impact, did not adequately convey the severity of a vulnerability that had been exploited in the wild, leading to severe consequences like device "bricking." By leveraging CVSS 4.0, specifically the Exploit Maturity: Attacked (E:A) metric alongside other CVSS 4.0 enhancements (like subsequent system impacts), the score was elevated to 9.1 (Critical). This score not only reflected the technical impact but also explicitly communicated the in-the-wild exploitation, satisfying the maintainer's need to convey the true gravity of the situation directly within the CVE record. This capability empowers vulnerability reporters to embed critical threat intelligence directly into the standardized scoring system.
Technical Deep Dive
▶ Watch: Explaining the three maturity levels: Attacked, PoC, Unreported (5:53)
The Exploit Maturity (E) metric is a distinctive feature of CVSS 4.0, residing within its Threat Metrics category. Unlike the Base Metrics, which describe the inherent characteristics of a vulnerability, Threat Metrics are designed to reflect the current state of exploitability and real-world activity. This makes 'E' a dynamic and highly influential factor in the final CVSS score.
The metric operates with three distinct levels, each representing a different state of exploit development and activity:
- Attacked (A): This is the highest severity level for Exploit Maturity. It signifies that the vulnerability has been exploited in the wild. This means there is concrete evidence of threat actors actively leveraging the vulnerability to compromise systems. When
E:Ais applied, it significantly increases the overall CVSS score, pushing it towards the "Critical" or "High" range, reflecting the immediate and elevated danger posed by active exploitation. The speaker notes that in CVSS 4.0, assumingE:Aby default (as some general data providers might) can lead to higher scores. - Proof of Concept (P): This intermediate level indicates that a publicly available Proof of Concept (PoC) exploit exists, but there is no confirmed evidence of its exploitation in the wild. A PoC demonstrates the feasibility of exploiting the vulnerability, making it a credible threat, but it hasn't yet been observed in active attacks. Applying
E:Pwill result in a lower score compared toE:A, but still higher thanE:U, acknowledging the increased risk posed by readily available exploit code. - Unreported (U): This is the lowest severity level for Exploit Maturity. It signifies that there is no public knowledge of a Proof of Concept and no public knowledge of exploitation attempts in the wild. This could range from a newly disclosed vulnerability with no public details to a vulnerability where only theoretical exploitability has been discussed. When
E:Uis applied, it results in the lowest possible score for the Exploit Maturity component, reflecting the least immediate threat from active exploitation.
The impact of Exploit Maturity on the overall CVSS 4.0 score is substantial. As demonstrated by Cunningham, changing 'E' from 'A' to 'P' or 'U' can shift a vulnerability from a "High" to a "Medium" severity, or even a "Critical" to a "High." This granularity provides a powerful lever for CNAs and security teams to fine-tune vulnerability assessments.
For instance, the speaker illustrated a denial-of-service attack that, if scored with E:A, would be a 7.1 (High). However, with E:P, it drops to 5.7 (Medium), and with E:U, it further decreases to 4.9 (Medium). This demonstrates how the 'E' metric directly influences the final numerical and qualitative severity.
Beyond its individual impact, Exploit Maturity integrates with other CVSS 4.0 enhancements. Cunningham briefly touches upon how, in the case of CVE 2023-39363, the ability to specify subsequent system impacts (e.g., E:A for Availability) alongside the E:A Exploit Maturity for the vulnerable system allowed for a more comprehensive and accurate representation of the severe "bricking" impact and real-world exploitation, ultimately leading to a 9.1 (Critical) score. This holistic approach in CVSS 4.0, with Exploit Maturity as a central component, enables a richer and more precise depiction of vulnerability risk.
Demo / Proof of Concept
▶ Watch: The problem of vulnerability overscoring in CVSS 4.0 (7:00)
While Shelby Cunningham's talk did not feature a live coding or tool demonstration, she presented a compelling real-world case study involving CVE 2023-39363 that effectively served as a proof of concept for the utility of Exploit Maturity in CVSS 4.0. This scenario highlighted how the new metric empowers maintainers and CNAs to accurately convey critical vulnerability information.
The situation involved a maintainer who approached GitHub with concerns about a vulnerability in their product that had been exploited in the wild and resulted in "bricking" (rendering devices inoperable). The maintainer felt that the existing CVSS 3.1 score did not adequately reflect the severe consequences and real-world impact of the attack.
Cunningham explained her process:
- Initial CVSS 3.1 Assessment: Even after attempting to re-score the vulnerability using CVSS 3.1, incorporating the high availability impact (bricking), the highest score she could achieve was 8.7 (High), an increase from an initial 6.5 (Medium). The maintainer, however, believed the situation warranted a "Critical" severity to truly reflect the gravity of the in-the-wild exploitation.
- Leveraging CVSS 4.0: Cunningham then turned to CVSS 4.0. By utilizing its new capabilities, specifically the Exploit Maturity: Attacked (E:A) metric and the ability to define subsequent system impacts (e.g.,
E:Afor Availability on subsequent systems, signifying the widespread nature of the bricking), she was able to elevate the score. - Achieving "Critical" Status: The combined application of
E:Aand other CVSS 4.0 metrics resulted in a score of 9.1 (Critical). This score finally aligned with the maintainer's perspective, effectively communicating two crucial pieces of information: "your device is going to be bricked" and "this has happened in the wild." - Maintainer Satisfaction and Public Visibility: The maintainer's response, "Shelby much more reasonable now," validated the approach. As a result, the updated advisory and CVE record for CVE 2023-39363 now prominently display the CVSS 4.0 score with
E:A. This crucial information is visible on platforms like cve.org, NVD (National Vulnerability Database), and the GitHub Advisory Database (GHSA), allowing anyone viewing the CVE record to immediately understand that the vulnerability has been actively exploited.
This case study powerfully demonstrated how Exploit Maturity provides a direct and standardized mechanism to embed critical threat intelligence—specifically, evidence of in-the-wild exploitation—into vulnerability scores, making them more actionable and representative of actual risk.
Defensive Implications
▶ Watch: Data showing CVSS 4.0 scores higher than 3.1 (8:00)
The introduction and strategic use of the Exploit Maturity (E) metric in CVSS 4.0 carry significant implications for defenders across various organizational roles, from vulnerability management teams to security operations centers.
For Vulnerability Management and Prioritization:
- Refined Prioritization: Defenders can use the
Emetric to refine their prioritization strategies. Vulnerabilities withE:A(Attacked) should immediately be escalated to the highest priority, triggering rapid response protocols. This provides a direct signal, embedded within the CVSS score, that a vulnerability is an active threat, potentially more urgent than a high-scoring vulnerability withE:U(Unreported) orE:P(Proof of Concept). - Mitigating Alert Fatigue: For vulnerabilities that might receive a high base score in CVSS 4.0 but lack evidence of in-the-wild exploitation,
E:PorE:Ucan temper the final score, preventing over-prioritization. This helps combat alert fatigue by allowing security teams to focus resources on the most imminent threats, rather than chasing every technically severe but unexploited vulnerability. - Contextual Risk Assessment: The
Emetric adds crucial context. A high CVSS score is concerning, but knowing if it's due to theoretical impact (E:U), available PoC (E:P), or active exploitation (E:A) allows for a more nuanced risk assessment and resource allocation. Organizations can establish policies to differentiate response times based on the 'E' value.
For CNAs and Vulnerability Reporters:
- Clearer Communication: CNAs and maintainers now have a powerful tool to communicate the true urgency of a vulnerability directly within the standardized CVSS string. Using
E:Afor actively exploited vulnerabilities ensures that downstream consumers immediately grasp the severity. - Maintainer Empowerment: As demonstrated by the CVE 2023-39363 example,
Eempowers maintainers to ensure their vulnerability reports accurately reflect the real-world impact and exploitation status, fostering trust and better collaboration with the security community. - Reducing Ambiguity: By explicitly stating the exploit maturity, CNAs can reduce ambiguity around a vulnerability's immediate threat level, leading to more consistent interpretation by various stakeholders.
Interoperability with Other Threat Intelligence:
- Cunningham acknowledges that external resources like CISA's Known Exploited Vulnerabilities (KEV) database and EPSS (Exploit Prediction Scoring System) still hold value. KEV is crucial for identifying vulnerabilities known to be actively exploited, while EPSS provides a probability score of future exploitation.
- The
Emetric in CVSS 4.0 doesn't replace these; rather, it complements them. For organizations whose tools might only parse base CVSS metrics, KEV and EPSS remain essential. However, for those capable of processing the full CVSS 4.0 string,Eoffers an integrated, immediate indicator of exploitation status, reducing the need for cross-referencing in initial triage. - The speaker also highlighted the philosophical difference: CVSS 4.0 with
E:Aallows for direct statement of exploitation, while EPSS provides a probability. Both are valuable but serve slightly different purposes.
The discussion around consistency, raised during the Q&A, is also a defensive implication. While perfect consistency across all software is challenging, the goal for defenders should be to advocate for and implement consistent application of the E metric within their own environments and, where possible, encourage its use by their upstream suppliers and CNAs. This standardization will maximize its utility in building a more accurate and actionable vulnerability landscape.
Key Takeaways
- CVSS 4.0's Potential for Overscoring: The new CVSS 4.0 framework can assign higher scores to vulnerabilities compared to CVSS 3.1, potentially leading to an increase in "critical" and "high" severity alerts and contributing to alert fatigue.
- Exploit Maturity (E) as a Corrective Tool: The Exploit Maturity (E) metric in CVSS 4.0 provides a vital mechanism to adjust vulnerability scores based on real-world exploitation status, helping to temper overscoring and align scores closer to expectations.
- Three Levels of Exploit Maturity: The 'E' metric has three distinct values—Attacked (A), Proof of Concept (P), and Unreported (U)—each significantly impacting the final CVSS score and reflecting the immediate threat level.
- Direct Communication of Exploitation:
E:Ais particularly powerful for explicitly signaling that a vulnerability has been exploited in the wild, providing crucial threat intelligence directly within the CVSS string itself, as demonstrated with CVE 2023-39363. - Empowering Maintainers and CNAs: Organizations like GitHub, acting as CNAs, can leverage Exploit Maturity to better represent maintainers' perspectives on vulnerability severity and to provide more accurate, actionable information to downstream consumers.
- Complementary to Existing Threat Feeds: While CISA's KEV and EPSS remain valuable, Exploit Maturity offers an integrated, immediate indicator of exploitation status within the CVSS framework, complementing, rather than replacing, these external intelligence sources.
About the Speaker(s)
Shelby Cunningham works on GitHub's advisory database, where she is responsible for curating a vast number of CVE records. This work directly feeds into generating Dependabot alerts, making her deeply familiar with the nuances of vulnerability scoring across various products and practices by different CNAs. As part of her duties, Cunningham also contributes to GitHub's role as a CNA, often scoring CVSS for maintainers who utilize GitHub's CVE request feature and may not have the expertise or desire to score vulnerabilities themselves. Her extensive experience in both consuming and producing CVSS scores provides her with a unique perspective on the challenges and opportunities presented by CVSS 4.0, particularly regarding the practical application of the Exploit Maturity metric.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent, practitioner-focused walkthrough of how the Exploit Maturity metric works in CVSS 4.0, delivered by someone who clearly does this work every day. Cunningham brings genuine operational credibility — she's not theorizing, she's describing the decisions she makes curating CVE records for GitHub's advisory database. The CVE-2023-39363 case study is the talk's strongest moment, illustrating a real maintainer conversation and a concrete scoring outcome. The problem is that this is a features-and-examples talk, not a research talk. It explains a documented CVSS 4.0 mechanism, works through some score comparisons, and advocates for wider adoption. That's useful for a VulnCon audience…
Heather Calloway (CISO) — SOLID
Shelby Cunningham delivers a technically competent and practically grounded walkthrough of the Exploit Maturity metric in CVSS 4.0. The core argument — that E:A/P/U gives vulnerability managers and CNAs a lever to correct the overscoring problem introduced by CVSS 4.0 and to embed exploitation status directly into the score — is useful and well-supported by concrete examples. This is a solid specialist talk for people who work in vulnerability management or CVE curation. It does not reach the level where it changes how security programs are governed, resourced, or accountable — but it does not try to, and it does not oversell itself.