Common Vulnerability Scoring System (CVSS)
Definition
A standardised scoring framework that rates vulnerability severity on a 0-10 scale using base metrics (attack vector, complexity, privileges required, user interaction, impact on confidentiality, integrity, and availability), temporal metrics, and environmental metrics. CVSS scores appear in penetration test reports as a common severity reference.
- Abbreviation
- CVSS
- Score range
- 0.0 to 10.0
- Maintained by
- FIRST (Forum of Incident Response and Security Teams)
- Metric groups
- Base, temporal, environmental
- Use in reports
- Common severity reference for penetration test findings
Common questions
Why do two organisations sometimes report different CVSS scores for the same vulnerability?+
The base score is fixed by the vulnerability's inherent properties, but temporal metrics (exploit maturity, patch availability) and environmental metrics (asset criticality, compensating controls in that specific environment) are optional and adjustable, so a tester's environmental context can shift the final score away from a vendor's published base score.
Does a high CVSS score always mean immediate remediation is required?+
Not automatically. CVSS measures technical severity, not business risk or exploitation likelihood in context, so many organisations combine it with exploit-availability data and asset criticality to prioritise patching rather than acting on the base score alone.
Related terms
- Attestation Letter
- A formal document issued by a qualified assessor, such as a PCI Qualified Security Assessor (QSA) or an ISO 27001 certification body,...
- Red Team Exercise
- A full-scope adversary simulation in which a team of testers uses the full range of attack techniques (technical, social engineering, and physical)...
- Remediation Verification Test
- A targeted re-test conducted after an organisation has applied fixes to vulnerabilities identified in the original penetration test. The re-test confirms that...
- Rules of Engagement (RoE)
- The written contract or pre-test agreement that defines the authorised scope, permitted techniques, excluded systems, test window, escalation contacts, and emergency stop...
- Scope Creep
- The unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system...