Common Vulnerability Scoring System (CVSS)

As is common with estimates, risk is assessed differently depending on the perception and experience of the pentester - even if they all refer to the same assessment scheme. However, regulatory bodies such as the Darmstadt Regional Council in particular require a uniform system, as they have to define concrete requirements and measures. As a result, they require pentesters to perform a risk assessment according to the Common Vulnerability Scoring System (CVSS). The CVSS is a metric evaluation scheme that assigns a vulnerability a rating between 0 and 10 based on its conditions of exploitation and its extent of damage. The score represents the outgoing risk of a vulnerability as follows:

Score Risiko
9,0 - 10 Critical
7,0 - 8,9 High
4,0 - 6,9 Medium
0,1 - 3,9 Low

A CVSS score can also be represented as a vector string. This is a short text representation of the values with which the risk of a vulnerability was derived. For example, a vulnerability would be rated with a 10.0 or in vector notation with CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H if it can be exploited in a service at any time via the Internet without access data. In addition, the outgoing damage would have to be the complete compromise of various IT systems, so that the three goals of information security (confidentiality, integrity and availability) would be violated. The CVSS vector mentioned above consists of the following features:

  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)

For a detailed description of the criteria and the calculation of the score, we would like to refer to the official documentation of the Common Vulnerability Scoring System: CVSS Calculator

binsec academy GmbH – Advanced Pentest Training Lab

binsec academy GmbH operates the Pentest Training Lab, a highly practical online platform dedicated to real penetration testing. Simulating complex corporate networks and advanced real-world attack scenarios within isolated lab environments, it is engineered to sharpen the skills of aspiring and professional penetration testers. Upon conquering our rigorous, fully practical examination, participants earn the distinguished Binsec Academy Certified Pentest Professional (BACPP) designation — proving their technical capability to methodically uncover and evaluate vulnerabilities in modern IT infrastructures.

Explore the Pentest Training Lab

binsec GmbH – Experts in Penetration Testing

As the operative pentesting core of the binsec group, binsec GmbH has provided high-end, human-led penetration testing since 2013. Rejecting automated scans, our permanently employed, certified senior pentest experts deliver manual deep-dive assessments of web applications, APIs, mobile apps, complex network infrastructures, cloud environments, and advanced red team simulations. Specializing in high-regulation sectors like Payment, Banking, and Healthcare, we provide clear risk evaluations and actionable reports to effectively assess your business-critical systems.

Get Manual Expert Penetration Testing Services

Contact

binsec GmbH
Clemensstraße 6-8
60487 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorized Officer: Dominik Sauer, Florian Zavatzki
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808