CVSS Severity Levels and Ratings Explained: How Scores Work and How to Use Them

Learn what CVSS is, how it scores vulnerabilities, and what severity ratings like Low, Medium, High, and Critical mean. Stay informed with the 2025 CVSS 4.0 update.

May 24, 2025 - 12:49
Updated: 8 days ago
111.7k
CVSS Severity Levels and Ratings Explained: How Scores Work and How to Use Them

Quick answer: CVSS, the Common Vulnerability Scoring System, rates a vulnerability's severity from 0.0 to 10.0. The ratings are None (0.0), Low (0.1 to 3.9), Medium (4.0 to 6.9), High (7.0 to 8.9) and Critical (9.0 to 10.0). The score comes from metrics such as attack vector, complexity and impact on confidentiality, integrity and availability. It measures severity, not your risk.

Key takeaways

  • Five ratings: None 0.0, Low 0.1 to 3.9, Medium 4.0 to 6.9, High 7.0 to 8.9, Critical 9.0 to 10.0.
  • CVSS is maintained by FIRST. v3.1 is still very common, and v4.0 (released 2023) changes the metrics and naming.
  • A 'CVSS score' is usually the Base score only. Threat and Environmental metrics refine it for real conditions.
  • Severity is not risk. Combine CVSS with exploit data (EPSS, CISA KEV), exposure and how important the asset is.
  • Learn to read a vector string. It is the real record of how the score was reached.

What is CVSS?

CVSS stands for Common Vulnerability Scoring System. It is an open standard, maintained by FIRST (the Forum of Incident Response and Security Teams), for describing how serious a software vulnerability is. Each vulnerability gets a vector string that records its characteristics and a numeric score from 0.0 to 10.0. Anyone can read the same vector and arrive at the same score, which is why the CVE and NVD records, scanners and vendor advisories all use it.

The standard documentation and calculators are on the FIRST CVSS page.

What are the CVSS severity levels?

The score maps to five qualitative ratings. These bands are the same in v3.x and v4.0.

ScoreRatingTypical reading
0.0NoneNo security impact
0.1 to 3.9LowHard to exploit or small impact
4.0 to 6.9MediumNeeds conditions such as local access or user action
7.0 to 8.9HighSerious impact, often remotely exploitable
9.0 to 10.0CriticalRemote, easy, high impact, often no login needed

The ratings are a labelling aid for dashboards. Real decisions need more than the label, as the later sections show.

How does CVSS v3.1 work?

CVSS v3.1 is still the version you will see on most CVE records. A full CVSS score has three metric groups, but the number people quote is nearly always the Base score.

Base metrics

These describe the flaw itself and do not change over time or between organisations.

MetricQuestion it answersValues
Attack Vector (AV)How far away can the attacker be?Network, Adjacent, Local, Physical
Attack Complexity (AC)Does success depend on conditions the attacker cannot control?Low, High
Privileges Required (PR)What access does the attacker need first?None, Low, High
User Interaction (UI)Must a user do something?None, Required
Scope (S)Does the impact cross a security boundary?Unchanged, Changed
Confidentiality, Integrity, Availability (C, I, A)How much damage to each?None, Low, High

Temporal and Environmental metrics

Temporal metrics (exploit code maturity, remediation level, report confidence) reflect how the situation changes over time. Environmental metrics let an organisation adjust the score for its own systems, using confidentiality, integrity and availability requirements and modified base values. Most public scores do not include them, so you have to add that context yourself.

How to read a vector string

A vector string packs the metrics into one line:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Read it left to right: version 3.1, attack over the network, low complexity, no privileges, no user interaction, scope unchanged, high impact on confidentiality, integrity and availability. This is the classic unauthenticated remote code execution flaw.

How is a 9.8 calculated? A worked example

The v3.1 formula uses fixed weights. For the vector above:

  • Impact sub-score base: ISS = 1 - (1 - 0.56) x (1 - 0.56) x (1 - 0.56) = 0.9148.
  • Impact (scope unchanged) = 6.42 x ISS = 5.873.
  • Exploitability = 8.22 x AV (0.85) x AC (0.77) x PR (0.85) x UI (0.85) = 3.887.
  • Base = round up(5.873 + 3.887) = round up(9.76) = 9.8.

Now change Scope to Changed (S:C), meaning the flaw lets the attacker escape the component's security boundary. The impact formula changes and the sum exceeds 10, so the score is capped at 10.0. That is why Log4Shell (CVE-2021-44228) is listed as 10.0 while many other unauthenticated remote code execution bugs are 9.8.

A second example is Heartbleed (CVE-2014-0160), which leaked memory but did not change data or availability. With C:H, I:N, A:N and everything else as above, the score is 7.5 (High). This is a good example of why you should read the impact metrics, not just the label.

You do not need to compute these by hand, but doing it once makes the numbers less mysterious. For real work use FIRST's official CVSS 3.1 calculator.

What changed in CVSS v4.0?

FIRST released CVSS v4.0 in 2023 to fix long-standing complaints about v3.x. Version 3.1 and 4.0 will exist side by side for a long time, so know both.

Areav3.1v4.0
GroupsBase, Temporal, EnvironmentalBase, Threat, Environmental, Supplemental
Exploit conditionsAttack ComplexityAttack Complexity plus a new Attack Requirements (AT) metric
ImpactOne set (C, I, A) plus ScopeImpact on the vulnerable system (VC, VI, VA) and on subsequent systems (SC, SI, SA); Scope removed
Time-based metricsTemporal (three metrics)Threat, with Exploit Maturity
Extra contextNoneSupplemental metrics such as Safety, Automatable and Recovery, which describe but do not change the score
NamingJust a scoreCVSS-B, CVSS-BT, CVSS-BE or CVSS-BTE, to show which metric groups were used

The nomenclature is useful. A bare "9.3" could be Base only or a refined score. Writing CVSS-B 9.3 or CVSS-BTE 7.1 tells the reader what it contains. The v4.0 vector starts with CVSS:4.0/ and has different metric names, so you cannot compare v3.1 and v4.0 scores directly. FIRST's CVSS 4.0 calculator is the reference tool. The NVD shows v4.0 scores where a provider has supplied them, but many older records only have v3.x or v2.

How did CVSS versions develop?

VersionReleasedNotes
v12005First published by FIRST
v22007Common in older records; no Scope or User Interaction metric
v3.02015Added Scope and User Interaction
v3.12019Clarified wording and definitions; same formula
v4.02023Attack Requirements, Threat group, Supplemental metrics

Why is severity not the same as risk?

CVSS Base tells you how bad a flaw could be in general. It does not know how you use the software. Risk depends on three more things: how likely it is to be exploited, whether the vulnerable system is exposed, and how much the asset matters to your business. A Critical flaw on a test machine with no network route is less urgent than a High one on an internet-facing payment server with exploits already circulating.

Common limits of CVSS to keep in mind:

  • It scores the flaw in isolation, not chains of flaws.
  • Base scores ignore your network controls and data value unless you add Environmental metrics.
  • Different analysts can assign slightly different vectors to the same issue.
  • Many flaws cluster in the High and Critical range, so the label alone does not give a ranking.

How should you use CVSS in practice?

  1. Start with the Base score and vector. Use it to filter noise, such as ignoring Low issues in a first pass.
  2. Add exploit evidence. FIRST's EPSS estimates the probability a vulnerability will be exploited in the next 30 days. The CISA Known Exploited Vulnerabilities catalog lists flaws seen exploited in the wild. A KEV entry should jump the queue.
  3. Add exposure. Is the service reachable from the internet, from a partner network, or only from a management VLAN?
  4. Add asset value. Rank systems holding customer data, payments or core operations higher.
  5. Record the decision. Patch by a date, apply a mitigation, or accept the risk with a named owner.

Compliance regimes also use scores. For example, PCI DSS external scans treat findings at CVSS 4.0 and above as failures, so check the current scanning guide if you work with card data. Always keep a record of which CVSS version and metric groups your report uses.

How do CVSS, CVE and other systems relate?

SystemWhat it isQuestion it answers
CVEAn identifier for a known vulnerabilityWhich flaw are we talking about?
CVSSSeverity scoreHow bad could it be?
EPSSProbability of exploitation in 30 daysHow likely is exploitation?
CISA KEVList of flaws exploited in the wildIs it being used against someone now?
Vendor scores (for example Tenable VPR)Proprietary priority scoresWhat does the vendor rank first?

See the CVE programme for how IDs are assigned, and CERT-In for advisories that apply to Indian organisations.

Best practices for teams

  • State the CVSS version and metric group on every report line.
  • Use Environmental or Threat metrics, or separate asset and exploit columns, so the number reflects your reality.
  • Set remediation targets by combined priority, not by label alone.
  • Re-score when new exploit information appears.
  • Train analysts to justify each metric, so scores stay consistent.

Next steps

Take three CVE records from the NVD, read the vectors and rebuild the scores in the official calculator, then decide which you would patch first and why. If you want to apply this in assessment reports, see our VAPT course. For related reading, see what vulnerability analysis involves and VAPT risk assessment questions.

Frequently Asked Questions

CVSS is the Common Vulnerability Scoring System, an open standard maintained by FIRST for rating the severity of software vulnerabilities on a 0.0 to 10.0 scale, with a vector string that records how the score was reached.

None is 0.0, Low is 0.1 to 3.9, Medium is 4.0 to 6.9, High is 7.0 to 8.9 and Critical is 9.0 to 10.0. These bands apply to both CVSS v3.x and v4.0.

Base metrics describe how the flaw can be exploited and what it can damage. In v3.1 they feed a fixed formula that combines an exploitability sub-score and an impact sub-score, then rounds up to one decimal. FIRST publishes an official calculator.

A CVE is an identifier for one publicly known vulnerability, such as CVE-2021-44228. CVSS is the scoring system that rates how severe that vulnerability is. CVE records and the NVD often list CVSS scores alongside the ID.

CVSS v4.0, released in 2023, adds Attack Requirements, separates impact on the vulnerable and subsequent systems, removes Scope, renames Temporal to Threat and adds Supplemental metrics such as Safety and Automatable that do not change the score.

No. A Critical flaw on an isolated test box may matter less than a High flaw on an internet-facing server that is actively exploited. Use CVSS with exploit evidence, exposure and asset value to set priority.

EPSS, the Exploit Prediction Scoring System from FIRST, estimates the probability that a vulnerability will be exploited in the next 30 days. CVSS rates severity, EPSS estimates likelihood, so using both gives a better patching order.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.