Every finding in a penetration test report carries a line like this:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
and a number next to it. The number is what gets quoted in meetings. The line is what should be read, because it says why the number is what it is.
CVSS, the Common Vulnerability Scoring System, is published by FIRST. Version 4.0 was released on 1 November 2023.
What the score measures
CVSS measures the severity of a vulnerability: how easy it is to exploit and how much damage exploitation does. It does not measure risk, which also depends on what the affected system is worth to you and on whether anyone is attacking it. The specification says so itself, and version 4.0 made the distinction visible in the names of the scores:
| Name | Built from | Answers |
|---|---|---|
| CVSS-B | Base metrics | How severe is the vulnerability as such? |
| CVSS-BT | Base and Threat | How severe, given what attackers are doing now? |
| CVSS-BE | Base and Environmental | How severe in our environment? |
| CVSS-BTE | All three | How severe here and now? |
A report of a penetration test normally gives CVSS-B, sometimes CVSS-BE when the tester knows the environment well. Vulnerability databases publish CVSS-B. If a score has no letters after it, assume B.
The base metrics
The first five describe how the attack is carried out.
| Metric | Values | Question |
|---|---|---|
| Attack Vector (AV) | Network, Adjacent, Local, Physical | From where can the attacker reach it? |
| Attack Complexity (AC) | Low, High | Must the attacker defeat a protection that is in place? |
| Attack Requirements (AT) | None, Present | Does the attack depend on conditions of the deployment, such as a race or a position in the network? |
| Privileges Required (PR) | None, Low, High | What access does the attacker need beforehand? |
| User Interaction (UI) | None, Passive, Active | Does someone else have to do something? |
Attack Requirements is new in version 4.0: it separates conditions of the environment from protections that have to be defeated. User Interaction now has three values: Passive means an ordinary action such as opening a page, Active means the victim has to do something unusual.
The next six describe the damage, to the vulnerable system and to subsequent systems that can be reached through it:
| Metric | Values |
|---|---|
| Confidentiality: VC, SC | High, Low, None |
| Integrity: VI, SI | High, Low, None |
| Availability: VA, SA | High, Low, None |
Version 3.1 had a metric named Scope for the effect on other systems. It was a source of disagreement between scorers and was replaced by the three explicit metrics for subsequent systems.
Reading the example
AV:N/AC:L/AT:N/PR:N/UI:N: reachable over the network, no protection to defeat, no special conditions, no account needed, nobody has to click anything. VC:H/VI:H/VA:H: full loss of confidentiality, integrity and availability of the vulnerable system. SC:N/SI:N/SA:N: no effect beyond it.
This vector scores 9.3, Critical. If the same vulnerability also gave full control over systems behind it, the last three metrics would be High and the score would be 10.0.
Change one letter and the meaning changes. PR:L instead of PR:N says that an account is needed: for a public service with free registration that changes little, for an internal system it changes a lot. The score changes much less than the meaning. This is why the vector is worth reading.
The scale
| Rating | Score |
|---|---|
| None | 0.0 |
| Low | 0.1 – 3.9 |
| Medium | 4.0 – 6.9 |
| High | 7.0 – 8.9 |
| Critical | 9.0 – 10.0 |
Threat and environment
Exploit Maturity (E) is the single threat metric: Attacked, Proof-of-Concept or Unreported. A vulnerability that is being exploited in the wild keeps its score; one for which no exploit is known scores lower.
The environmental metrics let you restate the base metrics for your deployment and say how much confidentiality, integrity and availability matter for the affected system. A critical vulnerability in a system that holds nothing of value and is reachable only from a test network is not critical for you, and the environmental score can show that.
Version 4.0 also adds supplemental metrics, such as Safety, Automatable and Recovery. They describe the vulnerability further and do not change the score.
What the score does not tell you
- Whether it will be attacked. For known vulnerabilities, EPSS estimates the probability of exploitation. Severity and probability together say more than either alone.
- What the system is worth. A Medium in the payment system can matter more than a Critical in the staging copy of a marketing page.
- What the chain does. Three Medium findings that combine into a takeover of an account are reported as three Mediums and as one attack path. Read both.
How to use it
Sort by the score first, then correct by what you know: the value of the asset, exposure to the internet, known exploitation, the chains in the report. When the priority you arrive at differs from the score, write down why. A good report does the same: it gives the score, the vector and, where the tester disagrees with the number, the reason.
How we rate and handle findings is described in the methodology.