[{"data":1,"prerenderedAt":136},["ShallowReactive",2],{"wissen-en-cvss":3,"wissen-related-en-cvss":123},{"id":4,"title":5,"body":6,"description":101,"extension":102,"lang":103,"meta":104,"navigation":105,"path":106,"related":107,"seo":111,"short":112,"sitemap":113,"stem":114,"synonyms":115,"updated":121,"__hash__":122},"wissenEn\u002Fen\u002Fwissen\u002Fcvss.md","CVSS (Common Vulnerability Scoring System)",{"type":7,"value":8,"toc":90},"minimark",[9,13,18,21,24,28,31,54,62,66,69,73,76,80,83,87],[10,11,12],"p",{},"CVSS (Common Vulnerability Scoring System) is an open standard maintained by the Forum of Incident Response and Security Teams (FIRST) that describes the technical severity of a vulnerability. A defined set of metrics produces a value between 0.0 and 10.0 together with a vector string that exposes every individual decision behind it. The current version is CVSS v4.0, published in 2023; in practice a great many scores are still issued under v3.1.",[14,15,17],"h2",{"id":16},"why-cvss-matters","Why CVSS matters",[10,19,20],{},"CVSS is the shared language in which vendors, authorities and security teams talk about vulnerabilities. Without it every organisation would have to define \"severe\" for itself, and no advisory would be comparable with another. Because the vector string carries every metric with it, a score can be checked rather than believed: you can see whether a 9.8 comes from a flaw that is exploitable over the network without authentication, or from one that requires local access.",[10,22,23],{},"What CVSS does not do matters just as much. The score describes severity if the vulnerability is exploited — not the likelihood that it will be, and not the value of the affected system. Working a list purely by CVSS treats a critical flaw in a niche product nobody attacks as urgently as one currently used in ransomware campaigns.",[14,25,27],{"id":26},"how-cvss-works","How CVSS works",[10,29,30],{},"The standard groups its metrics into three layers, only the first of which feeds the commonly quoted score:",[32,33,34,42,48],"ul",{},[35,36,37,41],"li",{},[38,39,40],"strong",{},"Base metrics:"," the immutable properties of the vulnerability. These cover the attack vector (network, adjacent network, local, physical), attack complexity, the privileges required, any user interaction needed, and the impact on confidentiality, integrity and availability.",[35,43,44,47],{},[38,45,46],{},"Threat metrics"," (called \"temporal\" in v3.1): the maturity of available exploits and of any remediation. They move the score over time.",[35,49,50,53],{},[38,51,52],{},"Environmental metrics:"," the adjustment to your own environment, for instance where a system is especially sensitive or shielded by segmentation.",[10,55,56,57,61],{},"The value runs from 0.0 to 10.0 and maps to severity bands: none (0.0), low (0.1–3.9), medium (4.0–6.9), high (7.0–8.9) and critical (9.0–10.0). The accompanying vector string — ",[58,59,60],"code",{},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H"," for a score of 9.8, for example — makes each judgement legible. CVSS v4.0 additionally separates the impact on the vulnerable system from the impact on subsequent systems and introduces attack requirements as a metric of its own.",[14,63,65],{"id":64},"how-blacklensio-uses-cvss","How blacklens.io uses CVSS",[10,67,68],{},"blacklens.io shows the CVSS v3 or v4 score on every finding that carries a CVE, alongside the EPSS score, CISA KEV status, the availability of public exploits or proof-of-concept code, and the CWE category. Prioritisation combines those signals rather than letting one number decide the order: a vulnerability with a high CVSS score but no sign of exploitation sits behind one that is demonstrably under attack. The platform's own severities (critical, high, medium, low, info) remain authoritative for the findings workflow.",[14,70,72],{"id":71},"does-cvss-replace-a-risk-assessment","Does CVSS replace a risk assessment?",[10,74,75],{},"No. CVSS rates the vulnerability, not the risk. Risk additionally requires the likelihood of exploitation, whether the affected system is reachable from the internet, the data it processes and any compensating controls already in place. CVSS provides one of those inputs.",[14,77,79],{"id":78},"is-a-cvss-score-of-98-automatically-an-emergency","Is a CVSS score of 9.8 automatically an emergency?",[10,81,82],{},"Not automatically, but it is almost always worth a look. A 9.8 usually means the flaw is reachable over the network, exploitable without privileges or user interaction, and results in a full loss of confidentiality, integrity and availability. What decides urgency from there is whether an affected system is genuinely exposed and whether an exploit exists.",[14,84,86],{"id":85},"what-changes-with-cvss-v40","What changes with CVSS v4.0?",[10,88,89],{},"CVSS v4.0 replaces the old scope metric with separate impacts on the vulnerable and on subsequent systems, adds attack requirements as a metric of its own, and distinguishes passive from active user interaction. It also states more clearly which metric groups went into a quoted score. Since many sources still publish v3.1 values, scores should always be cited together with their version.",{"title":91,"searchDepth":92,"depth":92,"links":93},"",3,[94,96,97,98,99,100],{"id":16,"depth":95,"text":17},2,{"id":26,"depth":95,"text":27},{"id":64,"depth":95,"text":65},{"id":71,"depth":95,"text":72},{"id":78,"depth":95,"text":79},{"id":85,"depth":95,"text":86},"CVSS explained: how the 0.0 to 10.0 score is produced, what the metric groups and severity bands mean, and why CVSS alone does not prioritise anything.","md","en",{},true,"\u002Fen\u002Fwissen\u002Fcvss",[108,109,110],"epss","cisa-kev","vulnerability-management",{"title":5,"description":101},"CVSS is an open standard maintained by FIRST that expresses the technical severity of a vulnerability as a value between 0.0 and 10.0, derived from a defined set of metrics.",{"loc":106},"en\u002Fwissen\u002Fcvss",[116,117,118,119,120],"Common Vulnerability Scoring System","CVSS score","base score","CVSS v3.1","CVSS v4.0","2026-09-22","Ns0JvnR8bUsBE4VyGVQLAY4Mfpiki-RiXxJe09_YWRM",[124,128,132],{"path":125,"title":126,"short":127},"\u002Fen\u002Fwissen\u002Fcisa-kev","CISA KEV (Known Exploited Vulnerabilities)","The CISA KEV catalogue is a list maintained by the US agency CISA of vulnerabilities proven to be exploited in real attacks, each with a remediation due date.",{"path":129,"title":130,"short":131},"\u002Fen\u002Fwissen\u002Fepss","EPSS (Exploit Prediction Scoring System)","EPSS is a scoring system by FIRST that estimates for every CVE the probability that it will actually be exploited within the next 30 days, as a value between 0 and 1.",{"path":133,"title":134,"short":135},"\u002Fen\u002Fwissen\u002Fvulnerability-management","Vulnerability Management","Vulnerability management is the ongoing process of detecting vulnerabilities in systems, prioritising them by risk, fixing them and evidencing the fix.",1790073258783]