AiVibe

Cybersecurity & Compliance

Common Vulnerability Scoring System (CVSS)

An open framework maintained by FIRST for rating the severity of software vulnerabilities on a scale from 0.0 to 10.0, based on how a vulnerability can be exploited and the impact it would have.

CVSS expresses a vulnerability's characteristics as a vector string of metric values and calculates a numerical score from them. Base metrics describe intrinsic properties such as attack vector, attack complexity, privileges required, user interaction and the impact on confidentiality, integrity and availability. Version 4.0, published in 2023 by the Forum of Incident Response and Security Teams (FIRST), groups metrics into base, threat, environmental and supplemental groups, while version 3.1, which uses base, temporal and environmental groups, remains widely used.

Vendors, the National Vulnerability Database and security tools publish CVSS scores so that organisations can compare and prioritise findings. Scores map to qualitative ratings: low from 0.1 to 3.9, medium from 4.0 to 6.9, high from 7.0 to 8.9 and critical from 9.0 to 10.0. Many patching policies and service-level agreements set remediation deadlines according to these ratings.

A base score measures severity, not risk: it ignores whether a vulnerability is being exploited, how exposed the affected asset is and how important that asset is to the business. FIRST recommends supplementing base scores with threat and environmental metrics, and many organisations also use exploit prediction data such as EPSS and lists of known exploited vulnerabilities. Scores for the same vulnerability can differ between vendors and the NVD.

Key points

Where AiVibe comes in

AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.

Explore AiVibe’s work in Cybersecurity & Compliance →

Related terms

Ask AiMuruga can explain Common Vulnerability Scoring System (CVSS) for your plant, product or security programme, and draw how it fits.