Common Vulnerability Scoring System (CVSS)
The Common Vulnerability Scoring System, or CVSS, is a standardised framework for assessing the severity of IT security vulnerabilities. It considers various characteristics of a vulnerability, including the required network access, attack complexity, necessary user interaction and potential impact on confidentiality, integrity and availability. The assessment produces a numerical CVSS score ranging from 0.0 to 10.0. A higher score indicates a more severe vulnerability. Organisations and IT security teams use CVSS as part of vulnerability management to assess security weaknesses and prioritise remediation activities. CVSS complements identification systems such as CVE by providing a standardised assessment of the technical severity of a vulnerability.