Vulnerability severity score
CVSS · A widely used scale that rates a vulnerability's technical severity from 0 to 10; the impact on your particular business still has to be judged separately.
- 01
Why it matters
A CVSS score describes a flaw's technical weight in a common language: can it be exploited remotely, does it need authentication, how does it affect data or service. The critical, high, medium and low labels in reports are usually based on it. The score is a starting point; the impact on your business is assessed separately.
- 02
Example
A flaw scored 9.8 is critical because it can be exploited over the internet without signing in. If the same flaw sits on a test server reachable only from the internal network and holding no sensitive data, its fix can be scheduled lower.
- 03
Common mistake
Ranking by score alone. Cases where two low-scored flaws combine into a critical path, or a high-scored flaw is unreachable in your environment, do not show up in the number.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.