DefinitionCVSS (Common Vulnerability Scoring System) is the open standard, maintained by FIRST, that gives each vulnerability a score from 0 to 10 based on its technical severity. It measures how serious the flaw is, not the risk to a specific company.
How it works
The current version is CVSS v4.0, published in November 2023. The score comes from metrics organized in groups:
- Base: intrinsic characteristics of the flaw, such as attack vector, privileges required and impact on confidentiality, integrity and availability.
- Threat: exploit maturity.
- Environmental: asset importance and the effect of the organization's controls.
- Supplemental: extra information that does not change the score.
The qualitative scale is: None (0.0), Low (0.1–3.9), Medium (4.0–6.9), High (7.0–8.9) and Critical (9.0–10.0). The score comes with a vector, such as CVSS:4.0/AV:N/AC:L/..., that shows each metric used in the calculation.
Severity is not risk
The score published in advisories is usually just the Base score. When the Threat and Environmental groups are not filled in, CVSS 4.0 assumes the worst case, so the Base score tends to be pessimistic. It also does not say whether the flaw is being exploited: two flaws with the same score can have very different chances of attack. That is what EPSS, which estimates the likelihood of exploitation, and the KEV catalog, which records confirmed exploitation, are for.
In practice
Use CVSS to understand how serious a flaw is, but not as the only prioritization rule. Always state the version and the groups used (CVSS 4.0 recommends labels such as CVSS-B or CVSS-BTE) and combine the score with asset criticality, EPSS and KEV.
Network Secure offers Vulnerability Management as a continuous service.
Frequently asked questions
What is the difference between CVSS and EPSS?
CVSS measures the technical severity of a vulnerability, from 0 to 10. EPSS estimates the likelihood it will be exploited in the next 30 days. One does not replace the other.
Should a vulnerability with a critical CVSS score be fixed first?
Not necessarily. A critical flaw with no known exploitation can go into the planned window, while a lower-scored flaw that is in the KEV catalog and exists on an exposed asset should come first.