GlossaryAttack surface and pentesting

CVSS

Short answer

CVSS (Common Vulnerability Scoring System) is the standard method for rating the severity of a software vulnerability on a scale from 0 to 10. It helps security teams compare vulnerabilities, but it measures technical severity, not the real risk for a specific organisation.

Severity bands

CVSS scores are grouped into bands: 0.1 to 3.9 is low, 4.0 to 6.9 is medium, 7.0 to 8.9 is high and 9.0 to 10.0 is critical. The score is calculated from factors such as how the vulnerability is exploited (over the network or locally), how complex the attack is, whether privileges or user interaction are needed, and the impact on confidentiality, integrity and availability.

Versions

CVSS version 3.1 is still the most widely used. Version 4.0, published in 2023, refines the metrics and adds more context about the threat and the environment.

The limits of CVSS

A base CVSS score describes how serious a vulnerability is in general, not how risky it is for a specific company. A critical score on an internal system that nobody can reach may matter less than a medium one on an internet facing server that attackers are already exploiting.

Using it well

Mature teams combine CVSS with exploitation data (EPSS, CISA KEV) and with the exposure and value of the affected asset to prioritise remediation by real risk.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub