CVSS Metrics Cheat Sheet

The eight CVSS v3.1 base metrics with their weights, the severity bands, six worked vector scores and how to use a score without misreading it.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page
On this page

CVSS, the Common Vulnerability Scoring System, rates how severe a security flaw is on a scale from 0.0 to 10.0. Each CVE usually carries a CVSS score so teams can decide what to patch first. This page covers version 3.1, the most widely quoted. Score a vector yourself with the CVSS Calculator.

The base metrics

A base score comes from eight metrics describing the flaw itself.

Metric Question it answers Values (weight)
Attack Vector AV How close must the attacker be? Network (0.85), Adjacent (0.62), Local (0.55), Physical (0.2)
Attack Complexity AC Do conditions outside the attacker's control have to line up? Low (0.77), High (0.44)
Privileges Required PR What access does the attacker need first? None (0.85), Low (0.62 / 0.68), High (0.27 / 0.5); the second number applies when Scope is Changed
User Interaction UI Must a victim do something, such as click a link? None (0.85), Required (0.62)
Scope S Can the flaw affect things beyond the vulnerable component? Unchanged, Changed
Confidentiality C How much data can be read? High (0.56), Low (0.22), None (0)
Integrity I How much data can be changed? High (0.56), Low (0.22), None (0)
Availability A Can the system be slowed or taken down? High (0.56), Low (0.22), None (0)

A vector string writes the choices compactly: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Severity ratings

Score Severity
0.0 None
0.1 - 3.9 Low
4.0 - 6.9 Medium
7.0 - 8.9 High
9.0 - 10.0 Critical

Worked examples

Scenario Vector Score Severity
Remote code execution with no login AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 Critical
Local privilege escalation by a logged-in user AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 7.8 High
Authenticated user can read other people's data AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 6.5 Medium
Reflected cross-site scripting AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 6.1 Medium
Data readable by someone holding the device AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.6 Medium
Hard-to-exploit minor information leak AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N 3.7 Low

Every score above was computed twice, once with the published formula and once with an independent CVSS library, and they agree.

How to use a score

  • It rates the flaw, not your risk. A "Critical" bug on a system that is not exposed may matter less than a "Medium" one on your login page. The base score ignores your environment.
  • Combine it with exploitability data. Whether an exploit is being used in the wild (for example in CISA's Known Exploited Vulnerabilities list) is often a better priority signal than the number alone.
  • Temporal and environmental metrics adjust the base score for exploit maturity, available fixes and the importance of the affected asset. Many scanners show only the base score.
  • Newer version. CVSS v4.0 adds metrics such as Attack Requirements and splits impact into the vulnerable and subsequent systems. Scores from different versions are not directly comparable.

Related: CVSS, Vulnerability and Zero-day.

Try these tools

See also

  • Glossary CVSS
    CVSS (Common Vulnerability Scoring System) is the standard way to rate how severe a vulnerability is, on a scale from 0.0 to 10.0.
  • Glossary CVE
    A CVE (Common Vulnerabilities and Exposures) is a unique identifier, such as CVE-2021-44228.
  • Glossary Vulnerability
    A vulnerability is a weakness in software, hardware or a process that an attacker could exploit to do something unintended.
  • Glossary Zero-day
    A zero-day is a vulnerability unknown to the software's maker, or without an available fix.
AdSense Placeholder
Slot: footer_leaderboard