Skip to content

CVSS (Common Vulnerability Scoring System)

Definition

An open standard maintained by FIRST (Forum of Incident Response and Security Teams) that assigns a numeric score from 0 to 10 to a published vulnerability. The score reflects attack vector, complexity, privileges required, user interaction, scope, and impact on confidentiality, integrity, and availability.

Maintained by
FIRST (Forum of Incident Response and Security Teams)
Score range
0 to 10
Inputs
Attack vector, complexity, privileges, user interaction, scope
Impact triad
Confidentiality, integrity, availability

Common questions

Does a high CVSS score mean a vulnerability is actively being exploited?+

No. CVSS measures the technical severity a successful exploit would have, not whether an exploit exists or is in use, which is why organizations also cross-check the CISA KEV catalogue before prioritizing a patch.

Why can the same CVE have a different effective severity in two different organizations?+

CVSS environmental and temporal metrics let an organization adjust the base score for its own exposure, such as whether the vulnerable service is internet-facing or isolated, so the practical risk can differ even though the base score is identical.

Related terms

Approved Scanning Vendor (ASV)
An organisation qualified by the PCI Security Standards Council to conduct external vulnerability scans of cardholder data environments. PCI-DSS requirement 11.3.2 mandates...
Audit Evidence
Any information the auditor uses to draw conclusions about a control. To be acceptable, audit evidence must be sufficient (enough of it),...
Remediation Prioritisation
The process of ordering vulnerability remediation by risk. Factors include CVSS base score, asset criticality, threat intelligence about active exploitation, and compensating...
Risk Acceptance
A formal decision by an authorised senior manager to tolerate a finding without full remediation, typically because the cost of remediation exceeds...
Vulnerability Assessment
A systematic process of identifying, classifying, and prioritising security weaknesses in systems, software, and infrastructure. Produces a list of findings with severity...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.