Diving into the CVSS Base Score Metrics - An Exploratory Analysis Bridging Product Security... @FIRSTdotorg
Diving into the CVSS Base Score Metrics - An Exploratory Analysis Bridging Product Security...  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 1 hour ago
Diving into the CVSS Base Score Metrics - An Exploratory Analysis Bridging Product Security Assessments and Real-World Attacks-

Kohei Taguchi (Panasonic Holdings Corporation, JP), Takayuki Uchiyama (Panasonic Holdings Corporation, JP), Yuichi Kikuchi (Panasonic Holdings Corporation, JP)

In recent years, the number of publicly disclosed vulnerabilities has continued to increase, making it increasing challenging for product vendors and developers to determine which security issues should be addressed with priority while considering resource constraints. CVSS Base Scores have traditionally been widely used as an indicator for prioritizing remediation efforts; however, its numerical value alone does not always sufficiently reflect risk to a particular organization, or which vulnerabilities attackers actually choose to exploit in real-world attacks. In this study, we attempt to explore the characteristics of vulnerabilities that attackers exploit, leveraging real-world attack data collected using an in-house developed IoT honeypot system. From this attack data, we analyzed the metrics that make up CVSS base scores to see if there are patterns in scoring for vulnerabilities that are exploited. In addition to this analysis, we correlated this with the vulnerability data obtained from pre-release product security assessments that have been conducted on in-house products for over 15 years. We will present insights into which vulnerabilities product vendors and developers should focus on and determining how to set remediation priorities.

---

Kohei Taguchi joined Panasonic in 2024 out of school and joined the global strategy team at the Product Security Center as his first job in the cyber security field. His daily work focuses on the analysis of IoT honeypot data and the monitoring of cybersecurity trends.

Taki Uchiyama is a member of Panasonic PSIRT. Main roles are the handling of vulnerabilities, creating and conducting product security training to product developers and providing assistance to product development teams.

Yuichi Kikuchi joined Panasonic in 2019 out of school and joined the vulnerability testing team at the Product Security Center as his first job in the cyber security field. His daily work involves vulnerability testing various products and devices for Panasonic business units and alongside that work he thinks about better ways to score and classify vulnerabilities.
Diving into the CVSS Base Score Metrics - An Exploratory Analysis Bridging Product Security...EU Cyber Resilience Act - A Product Owner’s ApproachContextual SBOMs: Unlocking Precise Vulnerability Management with Build-Time Content IntelligenceThe AI Arms Race in Vulnerability Management, Who’s Winning?Disparate Data, Distorted Decisions: Vendor Data Bias in CTIImproving Security Across Nations with FIRST: Enrico Lovat, FIRST MemberImproving Security Across Nations with FIRST: Cornelia Shipindo, FIRST MemberThe Clock is Ticking: CRA Compliance at ScaleAI Systems Are Software SystemsWhat Can Threat Intel Teams Learn from Journalists?The Myth of the Meteoric Rise in VulnerabilitiesSeeing Through the Fog: Interpreting Entra ID Signals During AiTM Attacks
FIRST |

Diving into the CVSS Base Score Metrics - An Exploratory Analysis Bridging Product Security...

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER