TopicCybersecurity →
Simple definition
A rating system used to express the technical severity of a vulnerability.
Technical definition
Common Vulnerability Scoring System combines several metrics to produce a score, often out of 10, representing in particular the impact and operating conditions.
What is it used for ?
Help to prioritise vulnerabilities with other context information.
Practical example
A 9.8 fault may be technically critical but may remain less urgent if the service is not exposed or used.
Common issues
- Prioritisation only by score
- different score depending on the version CVSS
- Business context not taken into account
Related terms
CVE · Vulnerability · Corrective management
Key takeaway: This entry explains the general operation of the term. Exact settings may vary depending on software, vendors and environments.