What Is CVSS? A Guide to Reading a Vulnerability Score Correctly
CVSS measures vulnerability severity from 0 to 10: 0-3.9 Low, 4-6.9 Medium, 7-8.9 High, 9-10 Critical. But the score alone is not priority. A severity band infographic, a metric table, exploitation based prioritization steps and FAQs.
Quick answer: CVSS (Common Vulnerability Scoring System) is a global scale that expresses how serious a vulnerability is with a standard number between 0 and 10. The score is divided into four severities: 0.0-3.9 Low, 4.0-6.9 Medium, 7.0-8.9 High, 9.0-10.0 Critical. The score is computed from the technical properties of the vulnerability: attack vector (remote or local), attack complexity, privileges required, user interaction and the impact on confidentiality, integrity, availability. The latest version is CVSS 4.0, which better reflects real world exploitation signals (threat and environmental metrics). But there is a critical caveat: CVSS alone is not priority. The urgency of a vulnerability depends, in addition to CVSS severity, on whether it is actually being exploited (CISA KEV list, EPSS probability) and on your business context. A 7.5 vulnerability under active exploitation can be more urgent than a 9.8 that no one is exploiting. The right approach: take the score as a starting point, prioritize with exploitability and business impact.
When a vulnerability scan produces hundreds of findings, the first question is: "Which one do I fix first?" CVSS brings a common language to this question; but read wrong, it misleads. This guide gathers CVSS, from score to priority, from severity to real world exploitation, into a single reference with world class clarity.
CVSS severity band
The right way to read the band is this: the color and number tell you the severity, but not the urgency. A critical vulnerability is the most dangerous in theory; but in practice which one is being exploited today, and which one affects your system, determines priority.
CVSS metrics and priority table
| Metric | The question it asks | Effect on score |
|---|---|---|
| Attack vector | Is it exploited remotely? | Remote = higher |
| Attack complexity | Easy or conditional? | Easy = higher |
| Privileges required | Works without privilege? | None = higher |
| User interaction | Must the victim click? | None = higher |
| Impact (C/I/A) | Loss of confidentiality/integrity/availability | Full loss = higher |
| Exploitation status (KEV/EPSS) | Is it actually exploited? | Decisive in priority |
Steps to prioritize a vulnerability correctly
- Look at CVSS severity. Critical and High pass the first filter.
- Check the exploitation signal. Is it on the CISA KEV list, is EPSS probability high? An exploited vulnerability moves up.
- Add business impact. Does it affect an internet facing, critical system? Context raises the score.
- Assess reachability. Is it actually reachable by an attacker, or isolated in the internal network?
- Plan the patch. Exploited criticals within hours, others in a planned window. Tie it to your secure software/DevSecOps processes.
- Verify. Rescan after patching; confirm the real risk is closed with a penetration test.
Even if a vulnerability has a high CVSS, you cannot prioritize it without tying it to MITRE ATT&CK techniques and real exploitation evidence; the score is a start, not a decision.
Frequently asked questions
Should I immediately fix every vulnerability with CVSS 9? Ideally yes, but in practice prioritization is needed. A 9 that is not exploited and not reachable by an attacker can come after an actively exploited 7. Evaluate the score together with exploitation and business impact.
What is the difference between CVSS and EPSS? CVSS measures how serious the vulnerability is (impact based). EPSS estimates the probability of exploitation in the near future (probability based). Together they prioritize much better.
What did CVSS 4.0 change? CVSS 4.0 more clearly added real world signals (threat and environmental metrics) alongside the base score and strengthened the "do not look at the base score alone" message. The goal is to bring the score closer to real risk.
What is the KEV list? It is CISA's "Known Exploited Vulnerabilities" list; it contains vulnerabilities confirmed to be actively exploited in the real world. A vulnerability on this list is urgent regardless of its score.
Sources
- FIRST, CVSS v4.0 Specification: https://www.first.org/cvss
- NIST NVD, Vulnerability Metrics: https://nvd.nist.gov/vuln-metrics/cvss
- CISA, Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- FIRST, EPSS: https://www.first.org/epss
For vulnerability management, CVSS and real exploitation based prioritization, a patch plan and verification, contact DSET. From our Ankara Hacettepe Teknokent laboratory we provide cybersecurity, penetration testing and digital forensics services.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.