Severity bands
CVSS scores are grouped into bands: 0.1 to 3.9 is low, 4.0 to 6.9 is medium, 7.0 to 8.9 is high and 9.0 to 10.0 is critical. The score is calculated from factors such as how the vulnerability is exploited (over the network or locally), how complex the attack is, whether privileges or user interaction are needed, and the impact on confidentiality, integrity and availability.
Versions
CVSS version 3.1 is still the most widely used. Version 4.0, published in 2023, refines the metrics and adds more context about the threat and the environment.
The limits of CVSS
A base CVSS score describes how serious a vulnerability is in general, not how risky it is for a specific company. A critical score on an internal system that nobody can reach may matter less than a medium one on an internet facing server that attackers are already exploiting.
Using it well
Mature teams combine CVSS with exploitation data (EPSS, CISA KEV) and with the exposure and value of the affected asset to prioritise remediation by real risk.




