ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Going beyond CVSS scores to secure cyber-physical systems

Amir Preminger at Claroty explains the importance of going beyond the Common Vulnerability Scoring System and prioritising exposure management in securing cyber-physical systems

 

The convergence of IT and OT systems has introduced several cyber-physical systems (CPS) across organisational networks. Systems such as digitally connected medical devices (IoMT) and industrial IoT (IIoT) have complicated the network landscape and expanded an organisation’s exposure to potential threats. 

 

These systems often operate outside the purview of IT security due to their specialised functions, legacy technology, and distinct operational requirements. Instead, they typically fall under the management of engineering, operations, or administrative departments, which may lack the cybersecurity expertise to manage these devices effectively. This leads to significant blind spots beyond the scope of traditional vulnerability assessments. 

 

In fact, Claroty’s Team82 recently revealed that 38% of the riskiest CPS assets are overlooked by traditional vulnerability management techniques. These assets often communicate directly over the internet without secure access solutions and harbour vulnerabilities that have already been publicly attacked. As a result, threat actors are often able to exploit these extended attack surfaces, laterally move into the core networks, and disrupt critical services. 

 

To address these blind spots, organisations need to understand the shortcomings of traditional cybersecurity approaches and rethink their risk management strategies. 

 

Blind spots in vulnerability management

Traditional vulnerability management strategies focus heavily on the Common Vulnerability Scoring System (CVSSv3.1) to prioritise remediation efforts. However, this method often misses key exposures in cyber-physical systems. Even the most risk-averse organisations often have severe blind spots when it comes to their actual exposure, and these blind spots don’t correlate directly with a critical CVSS score. 

 

For instance, our research found that 20% of OT and IoMT devices have CVSS scores of 9.0 or above, making them appear as high priorities. Yet, this volume is overwhelming and impractical for most organisations to manage effectively, especially given the limited maintenance windows for CPS assets.

 

More critically, 1.6% of OT and IoMT devices are defined as "high risk," having insecure internet connections and containing at least one Known Exploited Vulnerability (KEV). These devices, though not always scoring high on CVSS, pose an immediate and significant threat because they are directly exposed to the internet and are already being targeted by attackers. The data shows that 38% of these ultra-high-risk devices do not have a CVSS score of 9.0 or above, meaning they fly under the radar of traditional vulnerability management systems.

 

This misalignment arises because CVSS scores primarily measure the severity of vulnerabilities based on technical factors, often neglecting the real-world context of the asset. Factors such as end-of-life status, weak or default passwords, insecure communication protocols, and the presence of sensitive data like Personally Identifiable Information (PII) or Protected Health Information (PHI) are crucial in determining the actual risk – yet they are not adequately addressed by CVSS scores alone. 

 

Consequently, organisations remain blind to some of their riskiest exposures, focusing their efforts on vulnerabilities that may be less likely to be exploited.

 

Threat actors exploit known vulnerabilities

Known vulnerabilities, especially those catalogued in databases like CISA’s Known Exploited Vulnerabilities (KEV), are attractive targets because they offer a lower barrier to entry for attackers. These vulnerabilities are well-documented, often with publicly available exploit code, making it easier for attackers to craft successful attacks without the need for sophisticated skills or resources.

 

Known vulnerabilities often come with publicly available exploit code, detailed descriptions, and sometimes even step-by-step guides on how to leverage them. This reduces the technical effort and time required for attackers to develop an effective attack. Additionally, older vulnerabilities frequently remain unpatched in many systems, particularly CPS and OT environments, where updating software can be complex and disruptive. This makes them reliable targets with a high probability of success.

 

Using known vulnerabilities also allows attackers to operate with lower risk. Zero-day exploits, while powerful, are valuable and costly to develop or acquire. Once a zero-day is used, it is likely to be quickly identified and patched by the vendor, rendering the exploit obsolete. Older vulnerabilities offer a stealthier approach, as they exploit weaknesses that security systems may not be actively monitoring. This makes known vulnerabilities a preferred choice for attackers seeking efficient, low-risk methods to breach systems and achieve their objectives.

 

Understanding and addressing these blind spots requires a paradigm shift in vulnerability management. Organisations must adopt a more comprehensive approach that considers both the technical severity and the contextual risk of each asset. This ensures a more accurate assessment of their true exposure and better prioritisation of remediation efforts.

 

Rethinking risk management strategies

To address the shortcomings of traditional vulnerability management, organisations must rethink and reprioritise their risk management strategies. Effective exposure management in critical infrastructure requires a comprehensive approach that considers both technical severity and contextual risk.

 

A shift from vulnerability management to exposure management is crucial. This approach focuses on identifying vulnerabilities and understanding how these vulnerabilities can be exploited in the context of the asset’s operational environment. For example, CPS assets often have unique characteristics, such as legacy systems, limited maintenance windows, and critical operational roles. These factors necessitate a more nuanced approach to risk management.

 

CPS-native solutions are essential for this shift. These solutions should include capabilities for thorough CPS discovery and vulnerability assessment. By leveraging multi-data collection methods and tailored risk calculations, organisations can accurately map all CPS assets, their communication paths, and vulnerabilities. This detailed profiling allows for a transparent and uniquely tailored risk framework, providing a more accurate picture of the true risk landscape.

 

Prioritising mitigation efforts based on contextual risk factors is also critical. Traditional vulnerability management often overwhelms organisations with a large volume of high CVSS scores without clear guidance on where to start. By focusing on exposure management, organisations can receive actionable recommendations that prioritise remediation efforts based on quantified outcomes. These outcomes should consider specific attack vectors, their likelihood of being exploited, and the potential impact if exploited.

 

Additionally, validating exposure scenarios beyond mere vulnerability assessments is vital. This includes using VEX (Vulnerability Exploitability eXchange) files, active scanning techniques, and consulting with Original Equipment Manufacturers (OEMs) to validate risk assessments and enable proper remediation techniques. This proactive approach ensures that organisations address the most imminent threats and reduce their attack surface effectively.

 

Overall, the importance of continuous threat exposure management cannot be overstated. As cyber threats evolve, so must the strategies to mitigate them. Continuous monitoring and assessment allow organisations to refine their priorities and adjust their defences in real-time.

 

This holistic strategy addresses the unique challenges of CPS and ensures that organisations remain ahead of potential threats and can respond promptly to emerging risks. 

 


 

Amir Preminger is VP Research at Claroty

 

Main image courtesy of iStockPhoto.com and chombosan


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543