CVSS (Common Vulnerability Scoring System)
Definition
An open standard maintained by FIRST (Forum of Incident Response and Security Teams) that assigns a numeric score from 0 to 10 to a published vulnerability. The score reflects attack vector, complexity, privileges required, user interaction, scope, and impact on confidentiality, integrity, and availability.
- Maintained by
- FIRST (Forum of Incident Response and Security Teams)
- Score range
- 0 to 10
- Inputs
- Attack vector, complexity, privileges, user interaction, scope
- Impact triad
- Confidentiality, integrity, availability
Common questions
Does a high CVSS score mean a vulnerability is actively being exploited?+
No. CVSS measures the technical severity a successful exploit would have, not whether an exploit exists or is in use, which is why organizations also cross-check the CISA KEV catalogue before prioritizing a patch.
Why can the same CVE have a different effective severity in two different organizations?+
CVSS environmental and temporal metrics let an organization adjust the base score for its own exposure, such as whether the vulnerable service is internet-facing or isolated, so the practical risk can differ even though the base score is identical.
Related terms
- Approved Scanning Vendor (ASV)
- An organisation qualified by the PCI Security Standards Council to conduct external vulnerability scans of cardholder data environments. PCI-DSS requirement 11.3.2 mandates...
- Audit Evidence
- Any information the auditor uses to draw conclusions about a control. To be acceptable, audit evidence must be sufficient (enough of it),...
- Remediation Prioritisation
- The process of ordering vulnerability remediation by risk. Factors include CVSS base score, asset criticality, threat intelligence about active exploitation, and compensating...
- Risk Acceptance
- A formal decision by an authorised senior manager to tolerate a finding without full remediation, typically because the cost of remediation exceeds...
- Vulnerability Assessment
- A systematic process of identifying, classifying, and prioritising security weaknesses in systems, software, and infrastructure. Produces a list of findings with severity...