CVSS, the Common Vulnerability Scoring System, rates how severe a security flaw is on a scale from 0.0 to 10.0. Each CVE usually carries a CVSS score so teams can decide what to patch first. This page covers version 3.1, the most widely quoted. Score a vector yourself with the CVSS Calculator.
The base metrics
A base score comes from eight metrics describing the flaw itself.
| Metric | Question it answers | Values (weight) |
|---|---|---|
Attack Vector AV |
How close must the attacker be? | Network (0.85), Adjacent (0.62), Local (0.55), Physical (0.2) |
Attack Complexity AC |
Do conditions outside the attacker's control have to line up? | Low (0.77), High (0.44) |
Privileges Required PR |
What access does the attacker need first? | None (0.85), Low (0.62 / 0.68), High (0.27 / 0.5); the second number applies when Scope is Changed |
User Interaction UI |
Must a victim do something, such as click a link? | None (0.85), Required (0.62) |
Scope S |
Can the flaw affect things beyond the vulnerable component? | Unchanged, Changed |
Confidentiality C |
How much data can be read? | High (0.56), Low (0.22), None (0) |
Integrity I |
How much data can be changed? | High (0.56), Low (0.22), None (0) |
Availability A |
Can the system be slowed or taken down? | High (0.56), Low (0.22), None (0) |
A vector string writes the choices compactly: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Severity ratings
| Score | Severity |
|---|---|
0.0 |
None |
0.1 - 3.9 |
Low |
4.0 - 6.9 |
Medium |
7.0 - 8.9 |
High |
9.0 - 10.0 |
Critical |
Worked examples
| Scenario | Vector | Score | Severity |
|---|---|---|---|
| Remote code execution with no login | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
9.8 | Critical |
| Local privilege escalation by a logged-in user | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
7.8 | High |
| Authenticated user can read other people's data | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
6.5 | Medium |
| Reflected cross-site scripting | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
6.1 | Medium |
| Data readable by someone holding the device | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
4.6 | Medium |
| Hard-to-exploit minor information leak | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
3.7 | Low |
Every score above was computed twice, once with the published formula and once with an independent CVSS library, and they agree.
How to use a score
- It rates the flaw, not your risk. A "Critical" bug on a system that is not exposed may matter less than a "Medium" one on your login page. The base score ignores your environment.
- Combine it with exploitability data. Whether an exploit is being used in the wild (for example in CISA's Known Exploited Vulnerabilities list) is often a better priority signal than the number alone.
- Temporal and environmental metrics adjust the base score for exploit maturity, available fixes and the importance of the affected asset. Many scanners show only the base score.
- Newer version. CVSS v4.0 adds metrics such as Attack Requirements and splits impact into the vulnerable and subsequent systems. Scores from different versions are not directly comparable.
Related: CVSS, Vulnerability and Zero-day.