Common Vulnerability Scoring System (CVSS)
An open framework maintained by FIRST for rating the severity of software vulnerabilities on a scale from 0.0 to 10.0, based on how a vulnerability can be exploited and the impact it would have.
CVSS expresses a vulnerability's characteristics as a vector string of metric values and calculates a numerical score from them. Base metrics describe intrinsic properties such as attack vector, attack complexity, privileges required, user interaction and the impact on confidentiality, integrity and availability. Version 4.0, published in 2023 by the Forum of Incident Response and Security Teams (FIRST), groups metrics into base, threat, environmental and supplemental groups, while version 3.1, which uses base, temporal and environmental groups, remains widely used.
Vendors, the National Vulnerability Database and security tools publish CVSS scores so that organisations can compare and prioritise findings. Scores map to qualitative ratings: low from 0.1 to 3.9, medium from 4.0 to 6.9, high from 7.0 to 8.9 and critical from 9.0 to 10.0. Many patching policies and service-level agreements set remediation deadlines according to these ratings.
A base score measures severity, not risk: it ignores whether a vulnerability is being exploited, how exposed the affected asset is and how important that asset is to the business. FIRST recommends supplementing base scores with threat and environmental metrics, and many organisations also use exploit prediction data such as EPSS and lists of known exploited vulnerabilities. Scores for the same vulnerability can differ between vendors and the NVD.
Key points
- Scores range from 0.0 to 10.0, with low, medium, high and critical ratings.
- Maintained by FIRST; version 4.0 was published in 2023.
- Base scores measure severity, not organisational risk.
- Threat and environmental metrics adapt a score to real context.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.