// Vulnerability Analysis AI guide

CVSS scoring basics

Read a CVSS vector, not just the number — what the base metrics mean, why the same score can matter differently in context, and how to use severity to prioritize.

CVSS turns a vulnerability into a 0.0–10.0 severity score. The number is convenient for sorting, but the value is in the vector behind it, which describes how the vulnerability behaves. Reading the vector is what separates useful triage from cargo-culting a number.

The base metrics

The base score is built from how the vulnerability is exploited and what it affects:

  • Attack Vector — is it exploitable over the network, or does it need local access?
  • Attack Complexity and Privileges Required — how hard is it, and does the attacker need an account?
  • User Interaction — does a victim have to click or do something?
  • Impact on Confidentiality, Integrity, and Availability — what actually happens if it works.

Why context changes everything

The base score assumes a reachable, default deployment. A 9.8 for a feature you have disabled may be a non-issue, while a 6.5 on your internet-facing authentication path may be your top priority. CVSS ranks the vulnerability in the abstract; you rank the risk to your system.

Using it to prioritize

Treat CVSS as a first-pass sort, then adjust for exposure, exploit availability, and the sensitivity of what the affected component touches. The score starts the conversation; it does not end it.

Related guides

How to read a CVEWhat the parts of a CVE record mean — the identifier, description, affected versions, references, and severity — and how to turn one into a decision about your own systems.

Terms used here

CVSS (Common Vulnerability Scoring System)An open standard for rating the severity of a vulnerability on a scale from 0.0 to 10.0. The score is derived from a vector of metrics describing how the vulnerability can be exploited and what impact it has, producing a comparable severity rating.CVE (Common Vulnerabilities and Exposures)A public catalog that assigns a unique identifier — for example CVE-2021-44228 — to a specific, publicly known vulnerability. A CVE record is the shared reference point defenders, vendors, and researchers use to talk about the same issue.VulnerabilityA flaw or weakness in a system that could be exploited to compromise its confidentiality, integrity, or availability. Not every vulnerability is equally serious; severity depends on how easily it can be exploited and what the impact would be.RemediationThe action taken to resolve a vulnerability — such as applying a patch, changing a configuration, or adding a control. A good vulnerability report includes remediation guidance so the owner knows not just what is wrong but how to fix it.