CVSS

Common Vulnerability Scoring System

Allgemeines Schwachstellen-Bewertungssystem

CVSS is the globally established, open standard for assessing the technical severity of a vulnerability on a scale from 0 to 10. It describes how easily a flaw can be exploited and what damage it can cause — but not how likely its actual exploitation is. CVSS and the complementary Exploit Prediction Scoring System (EPSS) deliberately answer different questions.

History. CVSS arose from the need to unify the mutually incompatible severity systems common before 2005. Version 1 appeared in February 2005; shortly afterwards the organisation Forum of Incident Response and Security Teams (FIRST) took over its development. There followed the long-dominant version 3.1 and finally the current version 4.0, published on 1 November 2023.

Facts. CVSS v4.0 is structured into four metric groups: Base (intrinsic properties), Threat (current threat situation), Environmental (the operator's environment) and Supplemental (additional guidance). The often solely cited Base score is only the starting point — only the Threat and Environmental metrics contextualise it for one's own environment. The numeric value translates into the levels Low, Medium, High and Critical.

Outlook & recommendation. The most common mistake in vulnerability management is patching by CVSS Base score alone: many critical values are never exploited, while some medium value is actively in circulation. Prioritisation becomes defensible only when CVSS (severity) is combined with Exploit Prediction Scoring System (EPSS) (exploitation likelihood), the Known Exploited Vulnerabilities Catalog (KEV) catalogue and one's own asset context — precisely the intersection a priority score performs.

CVSS — Common Vulnerability Scoring System