Common Vulnerability Scoring System (CVSS)

As is common with estimates, risk is assessed differently depending on the perception and experience of the pentester - even if they all refer to the same assessment scheme. However, regulatory bodies such as the Darmstadt Regional Council in particular require a uniform system, as they have to define concrete requirements and measures. As a result, they require pentesters to perform a risk assessment according to the Common Vulnerability Scoring System (CVSS). The CVSS is a metric evaluation scheme that assigns a vulnerability a rating between 0 and 10 based on its conditions of exploitation and its extent of damage. The score represents the outgoing risk of a vulnerability as follows:

Score Risiko
9,0 - 10 Critical
7,0 - 8,9 High
4,0 - 6,9 Medium
0,1 - 3,9 Low

A CVSS score can also be represented as a vector string. This is a short text representation of the values with which the risk of a vulnerability was derived. For example, a vulnerability would be rated with a 10.0 or in vector notation with CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H if it can be exploited in a service at any time via the Internet without access data. In addition, the outgoing damage would have to be the complete compromise of various IT systems, so that the three goals of information security (confidentiality, integrity and availability) would be violated. The CVSS vector mentioned above consists of the following features:

  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)

For a detailed description of the criteria and the calculation of the score, we would like to refer to the official documentation of the Common Vulnerability Scoring System: CVSS Calculator

Section Navigation

binsec academy GmbH – Advanced Pentest Training Lab

binsec academy GmbH operates the Pentest Training Lab, a highly practical online platform dedicated to real penetration testing. Simulating complex corporate networks and advanced real-world attack scenarios within isolated lab environments, it is engineered to sharpen the skills of aspiring and professional penetration testers. Upon conquering our rigorous, fully practical examination, participants earn the distinguished Binsec Academy Certified Pentest Professional (BACPP) designation — proving their technical capability to methodically uncover and evaluate vulnerabilities in modern IT infrastructures.

Explore the Pentest Training Lab

binsec GmbH – Experts in Penetration Testing

binsec GmbH is a highly specialized penetration testing provider and the operative pentesting core of the binsec group. Since 2013, the company has focused exclusively on high-end, human-led penetration tests (pentests) and advanced red team simulations. Rejecting automated scans, our team of permanently employed, certified senior pentest experts delivers manual deep-dive assessments of critical digital systems: from web applications and APIs to mobile apps, complex network infrastructures, and cloud environments. As a dedicated assessment partner for highly regulated sectors such as Payment, Banking, and Healthcare, binsec GmbH provides clear risk evaluations and actionable reports to effectively secure business-critical systems.

Get Manual Expert Penetration Testing Services

Contact

binsec GmbH
Clemensstraße 6-8
60487 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorized Officer: Dominik Sauer, Florian Zavatzki
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808