CVSS - metrics

The Common Vulnerability Scoring System (CVSS) is a standardized framework used to assess the severity of software vulnerabilities. It helps organizations prioritize remediation efforts by providing a numerical score that reflects the intrinsic characteristics of a vulnerability. CVSS is composed of four metric groups:

Base Metrics / Impact Metrics

The intrinsic qualities of a vulnerability

Threat Metrics

These metrics reflect the characteristics of a vulnerability that change over time. They include:

Environmental Metrics

These metrics represent the characteristics of a vulnerability that are unique to a user’s environment. They include:

Supplemental Metrics