
Fix the Right CVEs First. Ignore the Noise.
VSAR scores vulnerability severity; SenninRecon prioritizes by operational context
VSAR (Vulnerability Situational Awareness Rating) is TXOne's vulnerability severity scoring methodology. It combines CVSS, EPSS, real-world attack telemetry from TXOne's global sensor network, and ongoing threat intelligence, updated daily. SenninRecon then layers asset exposure, compensating controls, virtual patch coverage, and operational criticality so your team works the CVEs that actually threaten operations, not the ones that score highest on a generic scale.
Every CVSS Critical Is Not an Actual Emergency.
CVSS tells you how bad a vulnerability could be in isolation. SenninRecon pairs VSAR severity scoring with operational context so you know how bad it is on your specific asset, right now.
A critical CVE on an air-gapped system with virtual patch coverage ranks lower than a moderate CVE on a network-facing asset. VSAR scores severity using CVSS, EPSS, real-world attack telemetry, and TXOne threat intelligence. SenninRecon then layers where the asset sits on the network, what protections already shield it, whether a TXOne virtual patch is in place, and how critical the asset is to operations, producing a prioritized list that reflects actual risk to your operation, not an abstract severity score.

Capability
What is VSAR?
VSAR is the vulnerability severity scoring methodology at the core of TXOne Sennin. It combines CVSS, EPSS, real-world attack telemetry from TXOne's global sensor network, and ongoing threat intelligence into a vulnerability severity score that updates daily. SenninRecon then layers asset inventory, protocol and network exposure, compensating control status, virtual patch coverage from TXOne Edge, and operational criticality to produce a prioritized remediation list. The CVEs that genuinely threaten your operation rise to the top with explicit evidence; the rest are de-prioritized with the same transparency. VSAR works alongside approval workflows in Sennin so that remediation proposals from the corporate security team are reviewed and approved by the site before anything deploys on the plant floor.
VSAR Challenges
Key challenges that VSAR addresses.
01 / 04
Every CVSS Critical Reads as Equal Urgency
CVSS scores a vulnerability's theoretical severity without knowing where it lives. A critical CVE on an isolated PLC and a critical CVE on an internet-facing HMI look identical to CVSS. Your OT team cannot patch both in the same week.
Every CVSS Critical Reads as Equal Urgency
CVSS scores a vulnerability's theoretical severity without knowing where it lives. A critical CVE on an isolated PLC and a critical CVE on an internet-facing HMI look identical to CVSS. Your OT team cannot patch both in the same week.
Key Components
Core components of the VSAR capability.
01 / 04
VSAR Severity Scoring With Operational Prioritization
VSAR scores vulnerability severity using CVSS, EPSS, real-world attack telemetry, and TXOne threat intelligence, updated daily. SenninRecon then layers network exposure, compensating controls, virtual patch coverage, and asset criticality. A critical CVE on an air-gapped system with virtual patch coverage can rank lower than a moderate CVE on a network-facing asset.
Key Capabilities
VSAR Severity Scoring With Operational Prioritization
VSAR scores vulnerability severity using CVSS, EPSS, real-world attack telemetry, and TXOne threat intelligence, updated daily. SenninRecon then layers network exposure, compensating controls, virtual patch coverage, and asset criticality. A critical CVE on an air-gapped system with virtual patch coverage can rank lower than a moderate CVE on a network-facing asset.
Key Capabilities
Outcomes
01 / 04
VSAR severity scores updated daily
VSAR severity scores updated daily
Why VSAR for OT Vulnerability Prioritization
CVSS-only scoring was designed for IT environments where patching is possible and context is generic. OT needs an operationally-weighted view.
CVSS does not know your network, your compensating controls, or your virtual patch coverage. SenninRecon does, because it reads directly from Edge, Stellar, Element, and Sennin telemetry and pairs it with VSAR severity scoring.
Legacy approach creates operational risk
When TXOne Edge is already blocking exploitation inline, the CVE is still tracked but its priority drops. Gartner's 2025 CPS Vulnerability analysis explicitly endorses virtual patching for environments that cannot patch directly.
Legacy approach creates operational risk
Approval workflows in Sennin mean corporate security proposes and the site approves before anything deploys. Remediation becomes a structured process instead of a friction point.
Legacy approach creates operational risk
26% of CISA advisories have no patch, 18% have neither patch nor mitigation. VSAR acknowledges that reality and scores the compensating control coverage instead of pretending patching is always available.
Legacy approach creates operational risk
SenninRecon correlates endpoint posture, network exposure, protocol inspection, and external scanner data, pairing those signals with VSAR severity scoring into one operationally-weighted risk score per asset. SIEM integration (Splunk, Microsoft Sentinel) feeds enterprise reporting without rework.
Legacy approach creates operational risk
See How VSAR Scores Your Environment
Schedule a VSAR walkthrough on a representative set of your assets. See how severity scoring plus operational prioritization reduces your CVSS critical backlog to the vulnerabilities that genuinely threaten production.