CVSS
CVSS, the Common Vulnerability Scoring System, rates how severe a vulnerability is from 0 to 10. What it measures, what it does not, and how to use it in a report.
Updated This page as Markdown
In short
CVSS (Common Vulnerability Scoring System) is an open standard maintained by FIRST that expresses the technical severity of a vulnerability as a number from 0.0 to 10.0 and a vector string. The base score rates the vulnerability itself, not the risk to a specific company. Versions 3.1 and 4.0 are in use; most scanners and advisories still report 3.1.
What is CVSS?
CVSS is a scoring system that turns the properties of a vulnerability into a severity number between 0.0 and 10.0. It is maintained by FIRST, the Forum of Incident Response and Security Teams, and used by vulnerability databases, scanners, product security teams and penetration testers to talk about severity in the same language.
A CVSS rating has two parts: the vector string, which records every metric that was chosen, for example CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and the score calculated from it, here 9.8. The vector is the important part. The number alone hides the reasoning.
Where is it defined?
The specification is published by FIRST and is free to use. Version 3.1 (2019) is the most widely deployed; version 4.0 (2023) changed the metric set and the calculation. Both define a base group (properties of the vulnerability that do not change), a temporal or threat group (exploit maturity, available fixes) and an environmental group (what the vulnerability means in a specific deployment).
Qualitative ratings are also defined by FIRST: 0.0 is None, 0.1 to 3.9 Low, 4.0 to 6.9 Medium, 7.0 to 8.9 High and 9.0 to 10.0 Critical.
What it means in practice
In a penetration test report every finding gets a base score and vector. That is what customers compare across reports and what many compliance frameworks ask for. Three things we see go wrong:
- Scores read as priorities. A Critical in a component nobody can reach from outside is not the first thing to fix. The environmental metrics exist for exactly this, but the simpler route is a short risk statement next to the score: who can reach it, what they get, whether it is exploited in the wild.
- Scope ignored. Scope: Changed (S:C) applies when a bug in one component lets the attacker affect another with its own security authority, for example a web application flaw that gives code execution on the host. It raises the score noticeably and is often set wrongly in both directions.
- Chains scored as single bugs. Two Medium findings that together give an attacker full access are, as a chain, a High or Critical. We score the individual findings and the chain separately.
For IoT and automotive products the base metrics need interpretation: physical access (AV:P) to a device that ships in millions of units is not the same as physical access to a server in a locked rack. Say so in the report.
Common misunderstandings
A CVSS score is not a probability of attack, not a measure of how easy the fix is, and not a regulatory requirement in itself. Regulations such as the Cyber Resilience Act require that vulnerabilities are handled and, for actively exploited ones, reported; they do not prescribe a scoring system. CVSS is simply the common way to describe severity when you do that.
FAQ
Frequently asked questions
Is a CVSS score the same as risk?
No. The base score describes the technical severity of the vulnerability on its own. Risk adds what the affected system does, how exposed it is and whether an exploit exists. CVSS has temporal and environmental metrics for that, but almost nobody fills them in. A 9.8 on an isolated test bench can be less urgent than a 6.5 on your customer portal.
Should I use CVSS 3.1 or 4.0?
Use the version your tooling and your customers use, and state it in the vector string. In 2026 most vulnerability databases, scanners and advisories still publish 3.1 scores; 4.0 adoption is growing. In our reports we give the 3.1 base score and vector for every finding and add 4.0 on request.
Why do two testers give the same bug different scores?
Because several metrics need judgement: whether privileges are required, whether a user has to interact, and whether the scope changes. The FIRST user guide settles most of these cases. A good report shows the vector, not just the number, so the reasoning can be checked.
Sources
Related pages
- Free toolsCVSS 3.1 CalculatorFree CVSS 3.1 calculator: pick the eight base metrics, get score, severity and vector string instantly. Paste an existing vector to decode it. Runs in your browser.
- GlossaryCVECVE (Common Vulnerabilities and Exposures) gives every public vulnerability one ID. How CVE records are created, what they contain and how to use them.
- ComparisonsPenetration Test vs Vulnerability Scan: What Each Finds and When to Use WhichA vulnerability scan finds known weaknesses automatically; a penetration test finds what a scanner cannot. Differences in depth and cost, and when to use which.
- ServicesWe break in. You get the proof and the fix.Hands-on penetration testing by OSCP-certified engineers: IoT devices, ECUs, industrial systems, web, cloud and networks. Fixed-price offer after a 15-min call.
