CVSS Severity Levels and Ratings Explained: How Scores Work and How to Use Them
Learn what CVSS is, how it scores vulnerabilities, and what severity ratings like Low, Medium, High, and Critical mean. Stay informed with the 2025 CVSS 4.0 update.
Quick answer: CVSS, the Common Vulnerability Scoring System, rates a vulnerability's severity from 0.0 to 10.0. The ratings are None (0.0), Low (0.1 to 3.9), Medium (4.0 to 6.9), High (7.0 to 8.9) and Critical (9.0 to 10.0). The score comes from metrics such as attack vector, complexity and impact on confidentiality, integrity and availability. It measures severity, not your risk.
Key takeaways
- Five ratings: None 0.0, Low 0.1 to 3.9, Medium 4.0 to 6.9, High 7.0 to 8.9, Critical 9.0 to 10.0.
- CVSS is maintained by FIRST. v3.1 is still very common, and v4.0 (released 2023) changes the metrics and naming.
- A 'CVSS score' is usually the Base score only. Threat and Environmental metrics refine it for real conditions.
- Severity is not risk. Combine CVSS with exploit data (EPSS, CISA KEV), exposure and how important the asset is.
- Learn to read a vector string. It is the real record of how the score was reached.
What is CVSS?
CVSS stands for Common Vulnerability Scoring System. It is an open standard, maintained by FIRST (the Forum of Incident Response and Security Teams), for describing how serious a software vulnerability is. Each vulnerability gets a vector string that records its characteristics and a numeric score from 0.0 to 10.0. Anyone can read the same vector and arrive at the same score, which is why the CVE and NVD records, scanners and vendor advisories all use it.
The standard documentation and calculators are on the FIRST CVSS page.
What are the CVSS severity levels?
The score maps to five qualitative ratings. These bands are the same in v3.x and v4.0.
| Score | Rating | Typical reading |
|---|---|---|
| 0.0 | None | No security impact |
| 0.1 to 3.9 | Low | Hard to exploit or small impact |
| 4.0 to 6.9 | Medium | Needs conditions such as local access or user action |
| 7.0 to 8.9 | High | Serious impact, often remotely exploitable |
| 9.0 to 10.0 | Critical | Remote, easy, high impact, often no login needed |
The ratings are a labelling aid for dashboards. Real decisions need more than the label, as the later sections show.
How does CVSS v3.1 work?
CVSS v3.1 is still the version you will see on most CVE records. A full CVSS score has three metric groups, but the number people quote is nearly always the Base score.
Base metrics
These describe the flaw itself and do not change over time or between organisations.
| Metric | Question it answers | Values |
|---|---|---|
| Attack Vector (AV) | How far away can the attacker be? | Network, Adjacent, Local, Physical |
| Attack Complexity (AC) | Does success depend on conditions the attacker cannot control? | Low, High |
| Privileges Required (PR) | What access does the attacker need first? | None, Low, High |
| User Interaction (UI) | Must a user do something? | None, Required |
| Scope (S) | Does the impact cross a security boundary? | Unchanged, Changed |
| Confidentiality, Integrity, Availability (C, I, A) | How much damage to each? | None, Low, High |
Temporal and Environmental metrics
Temporal metrics (exploit code maturity, remediation level, report confidence) reflect how the situation changes over time. Environmental metrics let an organisation adjust the score for its own systems, using confidentiality, integrity and availability requirements and modified base values. Most public scores do not include them, so you have to add that context yourself.
How to read a vector string
A vector string packs the metrics into one line:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Read it left to right: version 3.1, attack over the network, low complexity, no privileges, no user interaction, scope unchanged, high impact on confidentiality, integrity and availability. This is the classic unauthenticated remote code execution flaw.
How is a 9.8 calculated? A worked example
The v3.1 formula uses fixed weights. For the vector above:
- Impact sub-score base: ISS = 1 - (1 - 0.56) x (1 - 0.56) x (1 - 0.56) = 0.9148.
- Impact (scope unchanged) = 6.42 x ISS = 5.873.
- Exploitability = 8.22 x AV (0.85) x AC (0.77) x PR (0.85) x UI (0.85) = 3.887.
- Base = round up(5.873 + 3.887) = round up(9.76) = 9.8.
Now change Scope to Changed (S:C), meaning the flaw lets the attacker escape the component's security boundary. The impact formula changes and the sum exceeds 10, so the score is capped at 10.0. That is why Log4Shell (CVE-2021-44228) is listed as 10.0 while many other unauthenticated remote code execution bugs are 9.8.
A second example is Heartbleed (CVE-2014-0160), which leaked memory but did not change data or availability. With C:H, I:N, A:N and everything else as above, the score is 7.5 (High). This is a good example of why you should read the impact metrics, not just the label.
You do not need to compute these by hand, but doing it once makes the numbers less mysterious. For real work use FIRST's official CVSS 3.1 calculator.
What changed in CVSS v4.0?
FIRST released CVSS v4.0 in 2023 to fix long-standing complaints about v3.x. Version 3.1 and 4.0 will exist side by side for a long time, so know both.
| Area | v3.1 | v4.0 |
|---|---|---|
| Groups | Base, Temporal, Environmental | Base, Threat, Environmental, Supplemental |
| Exploit conditions | Attack Complexity | Attack Complexity plus a new Attack Requirements (AT) metric |
| Impact | One set (C, I, A) plus Scope | Impact on the vulnerable system (VC, VI, VA) and on subsequent systems (SC, SI, SA); Scope removed |
| Time-based metrics | Temporal (three metrics) | Threat, with Exploit Maturity |
| Extra context | None | Supplemental metrics such as Safety, Automatable and Recovery, which describe but do not change the score |
| Naming | Just a score | CVSS-B, CVSS-BT, CVSS-BE or CVSS-BTE, to show which metric groups were used |
The nomenclature is useful. A bare "9.3" could be Base only or a refined score. Writing CVSS-B 9.3 or CVSS-BTE 7.1 tells the reader what it contains. The v4.0 vector starts with CVSS:4.0/ and has different metric names, so you cannot compare v3.1 and v4.0 scores directly. FIRST's CVSS 4.0 calculator is the reference tool. The NVD shows v4.0 scores where a provider has supplied them, but many older records only have v3.x or v2.
How did CVSS versions develop?
| Version | Released | Notes |
|---|---|---|
| v1 | 2005 | First published by FIRST |
| v2 | 2007 | Common in older records; no Scope or User Interaction metric |
| v3.0 | 2015 | Added Scope and User Interaction |
| v3.1 | 2019 | Clarified wording and definitions; same formula |
| v4.0 | 2023 | Attack Requirements, Threat group, Supplemental metrics |
Why is severity not the same as risk?
CVSS Base tells you how bad a flaw could be in general. It does not know how you use the software. Risk depends on three more things: how likely it is to be exploited, whether the vulnerable system is exposed, and how much the asset matters to your business. A Critical flaw on a test machine with no network route is less urgent than a High one on an internet-facing payment server with exploits already circulating.
Common limits of CVSS to keep in mind:
- It scores the flaw in isolation, not chains of flaws.
- Base scores ignore your network controls and data value unless you add Environmental metrics.
- Different analysts can assign slightly different vectors to the same issue.
- Many flaws cluster in the High and Critical range, so the label alone does not give a ranking.
How should you use CVSS in practice?
- Start with the Base score and vector. Use it to filter noise, such as ignoring Low issues in a first pass.
- Add exploit evidence. FIRST's EPSS estimates the probability a vulnerability will be exploited in the next 30 days. The CISA Known Exploited Vulnerabilities catalog lists flaws seen exploited in the wild. A KEV entry should jump the queue.
- Add exposure. Is the service reachable from the internet, from a partner network, or only from a management VLAN?
- Add asset value. Rank systems holding customer data, payments or core operations higher.
- Record the decision. Patch by a date, apply a mitigation, or accept the risk with a named owner.
Compliance regimes also use scores. For example, PCI DSS external scans treat findings at CVSS 4.0 and above as failures, so check the current scanning guide if you work with card data. Always keep a record of which CVSS version and metric groups your report uses.
How do CVSS, CVE and other systems relate?
| System | What it is | Question it answers |
|---|---|---|
| CVE | An identifier for a known vulnerability | Which flaw are we talking about? |
| CVSS | Severity score | How bad could it be? |
| EPSS | Probability of exploitation in 30 days | How likely is exploitation? |
| CISA KEV | List of flaws exploited in the wild | Is it being used against someone now? |
| Vendor scores (for example Tenable VPR) | Proprietary priority scores | What does the vendor rank first? |
See the CVE programme for how IDs are assigned, and CERT-In for advisories that apply to Indian organisations.
Best practices for teams
- State the CVSS version and metric group on every report line.
- Use Environmental or Threat metrics, or separate asset and exploit columns, so the number reflects your reality.
- Set remediation targets by combined priority, not by label alone.
- Re-score when new exploit information appears.
- Train analysts to justify each metric, so scores stay consistent.
Next steps
Take three CVE records from the NVD, read the vectors and rebuild the scores in the official calculator, then decide which you would patch first and why. If you want to apply this in assessment reports, see our VAPT course. For related reading, see what vulnerability analysis involves and VAPT risk assessment questions.
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0