Common Vulnerability Scoring System

CVSS logo

The Common Vulnerability Scoring System (CVSS) is a free and open industry standard for assessing the severity of computer system security vulnerabilities. CVSS attempts to assign severity scores to vulnerabilities, allowing responders to prioritize responses and resources according to threat. Scores are calculated based on a formula that depends on several metrics that approximate ease and impact of an exploit. Scores range from 0 to 10, with 10 being the most severe. While many use only the CVSS Base score for determining severity, temporal and environmental scores also exist, to factor in availability of mitigations and how widespread vulnerable systems are within an organization, respectively.

The current version of CVSS (CVSSv4.0) was released in November 2023.[1]

CVSS is not intended to be used as a method for patch management prioritization, but is used like that regardless.[2]

  1. ^ "FIRST has officially published the latest version of the Common Vulnerability Scoring System (CVSS v4.0)". FIRST. Archived from the original on 2023-11-01.
  2. ^ Spring, J. M.; Hatleback, E.; Manion, A.; Shick, D. (December 2018). "Towards improving CVSS" (PDF). Carnegie Mellon University Technical Reports.