Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

How do you set risk score for pentest vulnerabilities which do no have CVE assigned?

0
Medium
Published: 08/15/2026 (08/15/2026, 03:51:14 UTC)
Source: Reddit Cybersecurity

Description

This content discusses the challenge of assigning risk scores to penetration testing findings that do not have associated CVE identifiers. It highlights the difficulty in applying frameworks like CISA KEV and EPSS, which focus on CVE-based vulnerabilities, to findings such as misconfigurations. The author seeks an objective, justifiable method for scoring such findings, noting that existing methodologies like the OWASP Risk Rating Methodology may lack accuracy for all cases.

Reddit Discussion

r/cybersecurity·posted by u/estrangedpulse
00

We are working on a system to be able to assign risk scores for various findings during the penetration tests. The idea is to use CVSS, CISA KEV and EPSS. The challenge I came across is that KEV and EPSS are mostly designed to get insight into likelihood of exploitation of CVEs, however in practice very often a security finding does not have CVE assigned.

Often its a misconfiguration of sorts, so how do you normally handle those types of findings? Do you still assign CVSS nevertheless and just ignore KEV/EPSS, and set the that manually? I would prefer a system where there is some sort of objective formula or system which allows different pentesters to select and define likelihood and impact in a way which can be justified.

On the other hand I don't want to use something like OWASP Risk Rating Methodology for all of the findings, since it lacks accuracy in my experience.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 04:26:08 UTC

Technical Analysis

The discussion centers on how to assign risk scores to penetration test findings lacking CVE assignments. While CVSS, CISA KEV, and EPSS provide frameworks for scoring vulnerabilities with CVEs, many findings, especially misconfigurations, do not have CVEs and thus fall outside these models. The author questions whether to assign CVSS scores manually and how to incorporate likelihood and impact in a consistent, objective manner. The post references the OWASP Risk Rating Methodology but notes its limitations in accuracy for all findings.

Potential Impact

There is no direct security vulnerability or exploit described. The impact relates to the challenge of accurately assessing and communicating risk for non-CVE findings during penetration tests, which can affect prioritization and remediation decisions.

Defensive Guidance

No specific vulnerability or exploit is described, so no direct mitigation applies. Organizations should consider developing or adopting risk scoring methodologies that can objectively assess findings without CVEs, potentially combining manual CVSS scoring with contextual likelihood and impact assessments. The referenced OWASP Risk Rating Methodology may be used as a baseline but may require adaptation for accuracy.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a7fea5cbf8831d53969428c

Added to database: 08/15/2026, 04:26:04 UTC

Last enriched: 08/15/2026, 04:26:08 UTC

Last updated: 08/15/2026, 14:41:08 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses