Menu

How CVSS v3.1 Works

The Common Vulnerability Scoring System (CVSS) translates complex security bugs into a standardized score from 0.0 to 10.0.

A vector string is structured into three core blocks of Base Metrics:

  1. Exploitability Metrics – How hard is it to exploit?
  2. Scope Metric – Does the blast radius stay contained?
  3. Impact Metrics – What does the attacker get if they succeed?

Reading the Vector String Step-by-Step

A CVSS vector uses key-value pairs separated by slashes (/). Here is how every metric slot works in practice, using the previous vector (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N) to show how each choice alters risk.

Group 1: Exploitability Metrics

Attack Vector – Where the attacker must be positioned:
N (Network)
A (Adjacent)
L (Local)
P (Physical)

Example: AV:N Network: Accessible anywhere over the internet. Highest risk level.

Attack Complexity – Conditions outside the attacker’s control required to succeed.
L (Low)
H (High)

Example: AC:H High: Requires special conditions (e.g., race conditions or specific network timing). Lowers total score. |

Privileges Required – Level of access or accounts needed before attacking.
N (None)
L (Low)
H (High)

Example: PR:N None: An unauthenticated stranger can attempt the exploit.

User Interaction – Whether a victim must help trigger the attack.
N (None)
R (Required)

Example: UI:N | None: Zero-click. The target system executes the exploit automatically.

Group 2: Scope Metric

Scope – Does the vulnerability spill over to impact other components?
U (Unchanged)
C (Changed)

Example: S:U Unchanged: Damage stays within the vulnerable application/component.

Group 3: Impact Metrics (The CIA Triad)

Confidentiality – Impact on data privacy and secrecy:
N (None)
L (Low)
H (High)

Example: C:H High: Total data exposure (e.g., full database dump or leaked private keys).

Integrity – Impact on data accuracy and modification rights.
N (None)
L (Low)
H (High)

Example: I:L Low: Attacker can alter some files/data, but cannot take total control.

Availability – Impact on system uptime and performance.
N (None)
L (Low)
H (High)

Example: A:N None: System won’t crash or suffer Denial-of-Service (DoS).

The Mechanics of Score Calculation

CVSS scores do not use simple addition. They use a weighted mathematical formula where:

  1. Impact drive the baseline: High damage across Confidentiality, Integrity, or Availability establishes the potential ceiling for the score.
  2. Exploitability acts as a multiplier: High complexity (AC:H), required privileges (PR:H), or required user interaction (UI:R) act as dampers that lower the final numerical score.

Example Rule: In our vector, even though Confidentiality loss is High (C:H) and requires no authentication (PR:N), the fact that Attack Complexity is High (AC:H) keeps the final score capped at 6.5 (Medium) instead of pushing into 7.0–8.9 (High).

Severity Rating Reference Scale

Score RangeSeverity RatingTypical Risk Profile
0.0NoneNo security impact
0.1-3.9LowMinimal impact; requires rare conditions or high local access.
4.0-6.9MediumSignificant impact, but constrained by high complexity or partial privileges.
7.0-8.9HighSerious exploitability with high impact; easily usable by attackers.
9.0-10.0Critical“Wormable” or trivially exploitable flaw causing total system takeover.