How to read a CVSS 4.0 score

What the number and the vector in a finding mean, which metrics they are built from, and why a score of 9.3 is not yet a priority.

Published5 min read

Every finding in a penetration test report carries a line like this:

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

and a number next to it. The number is what gets quoted in meetings. The line is what should be read, because it says why the number is what it is.

CVSS, the Common Vulnerability Scoring System, is published by FIRST. Version 4.0 was released on 1 November 2023.

What the score measures

CVSS measures the severity of a vulnerability: how easy it is to exploit and how much damage exploitation does. It does not measure risk, which also depends on what the affected system is worth to you and on whether anyone is attacking it. The specification says so itself, and version 4.0 made the distinction visible in the names of the scores:

Name Built from Answers
CVSS-B Base metrics How severe is the vulnerability as such?
CVSS-BT Base and Threat How severe, given what attackers are doing now?
CVSS-BE Base and Environmental How severe in our environment?
CVSS-BTE All three How severe here and now?

A report of a penetration test normally gives CVSS-B, sometimes CVSS-BE when the tester knows the environment well. Vulnerability databases publish CVSS-B. If a score has no letters after it, assume B.

The base metrics

The first five describe how the attack is carried out.

Metric Values Question
Attack Vector (AV) Network, Adjacent, Local, Physical From where can the attacker reach it?
Attack Complexity (AC) Low, High Must the attacker defeat a protection that is in place?
Attack Requirements (AT) None, Present Does the attack depend on conditions of the deployment, such as a race or a position in the network?
Privileges Required (PR) None, Low, High What access does the attacker need beforehand?
User Interaction (UI) None, Passive, Active Does someone else have to do something?

Attack Requirements is new in version 4.0: it separates conditions of the environment from protections that have to be defeated. User Interaction now has three values: Passive means an ordinary action such as opening a page, Active means the victim has to do something unusual.

The next six describe the damage, to the vulnerable system and to subsequent systems that can be reached through it:

Metric Values
Confidentiality: VC, SC High, Low, None
Integrity: VI, SI High, Low, None
Availability: VA, SA High, Low, None

Version 3.1 had a metric named Scope for the effect on other systems. It was a source of disagreement between scorers and was replaced by the three explicit metrics for subsequent systems.

Reading the example

AV:N/AC:L/AT:N/PR:N/UI:N: reachable over the network, no protection to defeat, no special conditions, no account needed, nobody has to click anything. VC:H/VI:H/VA:H: full loss of confidentiality, integrity and availability of the vulnerable system. SC:N/SI:N/SA:N: no effect beyond it.

This vector scores 9.3, Critical. If the same vulnerability also gave full control over systems behind it, the last three metrics would be High and the score would be 10.0.

Change one letter and the meaning changes. PR:L instead of PR:N says that an account is needed: for a public service with free registration that changes little, for an internal system it changes a lot. The score changes much less than the meaning. This is why the vector is worth reading.

The scale

Rating Score
None 0.0
Low 0.1 – 3.9
Medium 4.0 – 6.9
High 7.0 – 8.9
Critical 9.0 – 10.0

Threat and environment

Exploit Maturity (E) is the single threat metric: Attacked, Proof-of-Concept or Unreported. A vulnerability that is being exploited in the wild keeps its score; one for which no exploit is known scores lower.

The environmental metrics let you restate the base metrics for your deployment and say how much confidentiality, integrity and availability matter for the affected system. A critical vulnerability in a system that holds nothing of value and is reachable only from a test network is not critical for you, and the environmental score can show that.

Version 4.0 also adds supplemental metrics, such as Safety, Automatable and Recovery. They describe the vulnerability further and do not change the score.

What the score does not tell you

  • Whether it will be attacked. For known vulnerabilities, EPSS estimates the probability of exploitation. Severity and probability together say more than either alone.
  • What the system is worth. A Medium in the payment system can matter more than a Critical in the staging copy of a marketing page.
  • What the chain does. Three Medium findings that combine into a takeover of an account are reported as three Mediums and as one attack path. Read both.

How to use it

Sort by the score first, then correct by what you know: the value of the asset, exposure to the internet, known exploitation, the chains in the report. When the priority you arrive at differs from the score, write down why. A good report does the same: it gives the score, the vector and, where the tester disagrees with the number, the reason.

How we rate and handle findings is described in the methodology.

Request

Tell us what needs testing

  • Website check free of charge
  • Reply within 1 business day
  • NDA before any technical detail
  • Fixed price for paid engagements
  • No obligation

Request an assessment

Describe the systems and the goal. A manager replies within 1 business day with clarifying questions and the next step.

Who to reply to

We reply to this address unless you choose another channel.

A sole proprietor writes their own name.

Preferred channel
What to assess
Services of interest

Choose all that apply.

Free check

We check your website free of charge

If we find no problems, you receive the report free of charge as well. You pay for the report only when we find problems, and its price depends on their number and severity.

Terms of the free website security check

Application security

Infrastructure and cloud

Adversary simulation

AI, Web3 and cryptography

Programs and assurance

Application security

Free website security check

We look at your website from the outside, the way an attacker does, and check whether it can be broken into: weak settings, outdated software, exposed files, unsafe forms. The check is free of charge.

Application security

Web application penetration testing

We try to break into your web application the way a real attacker would: log in to the accounts of other people, read the data of other customers, change prices or orders. You learn what is possible before criminals do.

Application security

API security testing

An API is the channel through which your app, your website and your partners exchange data with your servers. We check that nobody can use it to read or change data that is not theirs.

Application security

Mobile application penetration testing

We examine your iOS or Android app and the servers behind it: what the app keeps on the phone, what can be extracted from it and whether its requests can be tampered with.

Application security

Secure code review

Our specialists read the source code of your product and find the mistakes that lead to a break-in, including those that cannot be seen from the outside.

Infrastructure and cloud

Cloud & Kubernetes security assessment

We check how your cloud is set up (AWS, Azure, Google Cloud, Kubernetes): who has access to what, which data is open to the internet and how far an attacker gets after the first mistake.

Infrastructure and cloud

Infrastructure penetration testing

We test your servers and your office network from the outside and from the inside: can an attacker get in, and once inside, reach the accounting system, the mail or the backups.

Infrastructure and cloud

External attack surface assessment

We find everything your company exposes to the internet, including what has been forgotten: old websites, test servers, leaked passwords. Then we show which of it can be attacked.

Infrastructure and cloud

CI/CD & supply chain security

We check the path your code takes from the developer to the customer: build servers, third-party libraries, access keys. Whoever controls that path controls your product.

Adversary simulation

Red team operations

A full-scale exercise. Our team plays a real attacker with a goal, for example to reach customer data, and you see whether your defence notices and stops it.

Adversary simulation

Purple team exercises

Our attackers and your defenders work side by side: we show an attack technique, your team checks whether it sees it, and the gaps in monitoring are closed on the spot.

Adversary simulation

Social engineering assessment

We test people, not machines: the phishing emails, calls and messages that attackers use to obtain passwords. You learn how many employees would be deceived and what to train.

AI, Web3 and cryptography

AI & LLM security testing

If your product has a chatbot or another AI model, we check whether it can be talked into revealing confidential data, breaking its own rules or acting on behalf of someone else.

AI, Web3 and cryptography

Smart contract audit

Before a smart contract holds money, we look for mistakes in its code that would let someone withdraw or freeze the funds. After deployment such mistakes cannot be corrected.

AI, Web3 and cryptography

Cryptography review

We check how your product encrypts data and protects keys: whether the right algorithms are chosen and whether they are applied correctly. A mistake here makes the encryption useless.

Programs and assurance

Bug bounty program management

A bug bounty is a program in which independent researchers look for vulnerabilities in your product and are paid for each one they find. We launch and run such a program for you.

Programs and assurance

Vulnerability disclosure program (VDP)

A public page and a procedure that tell researchers how to report a vulnerability to you safely. Without them reports get lost or arrive as threats. We set the process up and handle incoming reports.

Programs and assurance

Continuous penetration testing

Instead of one test a year, we test every significant change of your product throughout the year, so that a new vulnerability does not wait for months to be found.

Programs and assurance

Compliance-driven penetration testing

A penetration test arranged so that an auditor, a regulator or a large customer accepts its report: PCI DSS, DORA, NIS2, ISO/IEC 27001, SOC 2.

Services of interest

Not sure yet

Choose this if you do not know which service you need. Describe the task in your own words, and a specialist will suggest the service in the reply.

Domain or URL of the website or of the main system to test, for example app.example.com.

What needs testing, why now, and any deadline or compliance requirement. No passwords, keys or vulnerability details.

Confirmations

Do not send credentials, keys or details of a vulnerability through this form. A secure channel is agreed after the first reply.

Automated abuse check