Standardised scoring system rating vulnerability severity from 0 to 10 (Common Vulnerability Scoring System).
CVSS (Common Vulnerability Scoring System) provides standardised severity ratings for vulnerabilities on a 0-10 scale. CVSS considers attack complexity, required privileges, user interaction, and potential impact on confidentiality, integrity, and availability. Scores are categorised as Low (0.1-3.9), Medium (4.0-6.9), High (7.0-8.9), and Critical (9.0-10.0). CVSS provides a starting point for prioritisation, but organisations should consider their specific context—a critical vulnerability in an isolated system may be lower priority than a high-severity vulnerability in a customer-facing application.
Why It Matters
The DSC Perspective:
CVSS scores help prioritise vulnerabilities, but shouldn't be the only factor. A 'critical' vulnerability on an air-gapped test system may matter less than a 'high' on your e-commerce platform. Use CVSS as a starting point, then apply business context.
