Kai Ole Hartwig

name of the term: CVSS
descriptions of the term:

Definition

Definition. CVSS (Common Vulnerability Scoring System) rates vulnerabilities by fixed criteria. These include attack vector, complexity, required privileges and impact on confidentiality, integrity and availability. The result is a value between 0.0 and 10.0 plus a vector string. The current version is 4.0, but 3.1 is still widely used.

Why it matters. The base score describes the flaw, not your environment. A 9.8 in a library that never sees user input weighs less than a 7.5 on a public endpoint. Anyone building patch gates therefore needs context: reachability, KEV status, exploit availability.

Example. A CI pipeline blocks images with findings from CVSS 7.0 upward when a fix exists. Findings without a fix are documented and reassessed once a patch appears.

Related. CVE, CISA KEV, RCE, SBOM

Synonyms: Common Vulnerability Scoring System, CVSS score
Type of term: acronym
Language of the term (2 char ISO code): en
Back