Attack Vector
How remotely an attacker can reach the vulnerable system.
Build an accurate severity vector, understand every decision, and keep or share the result securely.
The intrinsic characteristics of the vulnerability and its direct impact.
How remotely an attacker can reach the vulnerable system.
Conditions outside the attacker's control that affect exploit reliability.
Deployment or execution conditions that must already exist for exploitation.
The privileges the attacker needs before exploitation.
Whether a user other than the attacker must take an action.
Confidentiality loss on the vulnerable system.
Integrity loss on the vulnerable system.
Availability loss on the vulnerable system.
Confidentiality impact beyond the vulnerable system.
Integrity impact beyond the vulnerable system.
Availability impact beyond the vulnerable system.
Current evidence about real-world exploitation maturity.
The current maturity and availability of exploit code or active exploitation.
Adjust the score for the importance and configuration of your environment.
Importance of confidentiality in this environment.
Importance of integrity in this environment.
Importance of availability in this environment.
Attack vector after environment-specific controls.
Attack complexity after environment-specific controls.
Attack requirements after environment-specific controls.
Required privileges in this environment.
Required user interaction in this environment.
Modified confidentiality impact on the vulnerable system.
Modified integrity impact on the vulnerable system.
Modified availability impact on the vulnerable system.
Modified confidentiality impact on subsequent systems.
Modified integrity impact on subsequent systems.
Modified availability impact on subsequent systems.
Extra context that does not change the numerical score.
Potential impact to human safety.
Whether the attack can be automated across targets.
Expected recovery behavior after an attack.
Resources obtained per exploitation event.
Expected effort for consumers to respond.
Vendor-provided urgency label.
CVSS describes technical severity. Prioritization should also consider exposure, asset importance, exploit evidence, and compensating controls. Metric guidance is a concise aid; consult the FIRST CVSS v4.0 specification for normative definitions.
Read the FIRST specification ↗