Common Vulnerability Scoring System
Common Vulnerability Scoring SystemWhat Is the Common Vulnerability Scoring System?
The common vulnerability scoring system is an open framework maintained by FIRST (Forum of Incident Response and Security Teams) that assigns numerical severity ratings to software vulnerabilities. It gives security teams a consistent, vendor-neutral language for communicating risk across organizations, tools, and processes.
Each vulnerability receives a score between 0.0 and 10.0, grouped into severity categories:
- None: 0.0
- Low: 0.1 to 3.9
- Medium: 4.0 to 6.9
- High: 7.0 to 8.9
- Critical: 9.0 to 10.0
This scoring system is embedded into nearly every vulnerability management platform, CVE database, and security advisory. When a new vulnerability is disclosed, its CVSS score is often the first data point security teams use to gauge urgency.
How CVSS Scores Are Calculated: Base, Temporal, and Environmental Metrics
CVSS scores are built from three metric groups, each capturing a different dimension of risk.
The Base Score reflects the intrinsic characteristics of a vulnerability, independent of time or environment. It factors in:
- Attack vector: whether exploitation requires local, adjacent, or network access
- Attack complexity: how much specialized effort is needed
- Privileges required: what level of access an attacker needs beforehand
- User interaction: whether a victim must take an action
- Scope: whether exploitation affects resources beyond the vulnerable component
- Confidentiality, integrity, and availability impact
The Temporal Score adjusts the Base Score based on factors that change over time, such as whether a public exploit exists or a patch has been released. The Environmental Score allows organizations to customize the rating based on their specific infrastructure, asset criticality, and existing security controls.
Together, these three layers make CVSS a flexible framework, though most organizations only reference the Base Score in practice.
CVSS v4: What Changed and Why It Matters
CVSS v4 was released in October 2023 and represents the most significant overhaul of the framework in over a decade. It introduced new metric groups and refined existing ones to better reflect modern threat environments.
Key changes in CVSS v4 include:
- A new Supplemental group for context like safety impact and recovery speed
- Refined attack complexity metrics, splitting out attack requirements as a separate factor
- Improved handling of vulnerabilities in operational technology and embedded systems
- More granular scoring for provider and end-user environments
CVSS v4 also introduced cleaner nomenclature. Scores are now labeled by their metric combination, such as CVSS-B for Base-only or CVSS-BE for Base plus Environmental, making it easier for teams to understand exactly what a published score reflects.
For organizations managing software bills of materials or tracking supply chain risk, CVSS v4 provides more precise inputs. Tools aligned with frameworks like the CIS framework can integrate these updated metrics to improve policy decisions.
Why CVSS Alone Is Not Enough for Vulnerability Prioritization
Despite its widespread adoption, CVSS was never designed to be the sole driver of vulnerability prioritization decisions. It does not account for whether a vulnerability is actually being exploited in the wild, how exposed a specific asset is, or how business-critical a system is.
Relying only on CVSS scores creates predictable problems:
- Critical-rated vulnerabilities may have no known public exploits and pose limited immediate risk
- Medium-rated vulnerabilities may already be actively weaponized in real attacks
- High volumes of Critical and High scores make it impossible to triage effectively without additional context
Security teams managing thousands of findings across containers, cloud workloads, or software supply chains cannot act on CVSS alone. Effective vulnerability prioritization requires layering in threat intelligence, asset context, and exploit probability data.
How to Use CVSS Alongside EPSS and Reachability Analysis
The Exploit Prediction Scoring System, or EPSS score, estimates the probability that a vulnerability will be exploited in the next 30 days based on threat intelligence signals. Pairing CVSS severity with an EPSS score allows teams to separate theoretical severity from observed exploit activity.
A practical workflow might look like this:
- Flag vulnerabilities with both a High or Critical CVSS score and an elevated EPSS score as immediate priorities
- Use reachability analysis to determine whether a vulnerable function is actually called in your code
- Deprioritize high CVSS findings where reachability analysis confirms no exploitable execution path
- Apply environmental scoring to reflect your specific asset exposure and compensating controls
Organizations building robust programs often reference SBOM generation tools to track which vulnerable components are present across their environments, making CVSS and EPSS data actionable at scale.
FAQs
What is the maximum CVSS score and what does it represent?
The maximum CVSS score is 10.0, classified as Critical severity. It represents a vulnerability that is remotely exploitable without authentication, requires no user interaction, and causes complete impact across confidentiality, integrity, and availability. A perfect 10 indicates the highest possible theoretical risk under the common vulnerability scoring system framework.
How often are CVSS scores updated after initial publication?
CVSS Base Scores can be revised after initial publication if new technical details emerge about a vulnerability. Temporal scores are expected to change as exploits are published or patches become available. However, updates are not always timely, and organizations should monitor advisories rather than assume published scores reflect the current threat landscape.
Who is responsible for assigning CVSS scores to new vulnerabilities?
CVSS scores are assigned by CVE Numbering Authorities, including the NVD, vendors, and authorized third parties. The National Vulnerability Database often publishes scores after a CVE is issued, though vendors may publish their own scores earlier. FIRST maintains the CVSS specification and provides certification for organizations that score vulnerabilities professionally.
How does CVSS handle vulnerabilities with no public exploit available?
CVSS Base Scores do not factor in exploit availability, which is captured under Temporal metrics instead. A vulnerability with no public exploit can still receive a Critical Base Score if its intrinsic characteristics are severe. This is one reason an EPSS score is valuable as a complement, since it reflects real-world exploit probability directly.
Do two vulnerabilities with equal CVSS scores always pose equal risk?
No. Equal CVSS scores do not imply equal risk. Two vulnerabilities may share a score of 8.5 but differ significantly in exploitability, target environment, and actual attacker interest. Vulnerability prioritization must consider asset exposure, business criticality, exploit activity, and reachability analysis to accurately compare and rank findings beyond raw CVSS values.






