SECURITY SCORING WORKSPACE · FIRST CVSS v4.0

CVSS v4.0 Calculator

Build an accurate severity vector, understand every decision, and keep or share the result securely.

✓ Server-validated scoring✓ Latest CVSS 4.0✓ No third-party scripts
CVSS v4.0 score 10.0 Critical Severity, not business risk
Vector stringCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Score verified by the server.
01

Base metrics

The intrinsic characteristics of the vulnerability and its direct impact.

AV

Attack Vector

How remotely an attacker can reach the vulnerable system.

AC

Attack Complexity

Conditions outside the attacker's control that affect exploit reliability.

AT

Attack Requirements

Deployment or execution conditions that must already exist for exploitation.

PR

Privileges Required

The privileges the attacker needs before exploitation.

UI

User Interaction

Whether a user other than the attacker must take an action.

VC

Vulnerable System Confidentiality

Confidentiality loss on the vulnerable system.

VI

Vulnerable System Integrity

Integrity loss on the vulnerable system.

VA

Vulnerable System Availability

Availability loss on the vulnerable system.

SC

Subsequent System Confidentiality

Confidentiality impact beyond the vulnerable system.

SI

Subsequent System Integrity

Integrity impact beyond the vulnerable system.

SA

Subsequent System Availability

Availability impact beyond the vulnerable system.

About the result

CVSS describes technical severity. Prioritization should also consider exposure, asset importance, exploit evidence, and compensating controls. Metric guidance is a concise aid; consult the FIRST CVSS v4.0 specification for normative definitions.

Read the FIRST specification ↗