What is CVSS (Common Vulnerability Scoring System)?
The Common Vulnerability Scoring System (CVSS) is a standard for assessing the criticality of security vulnerabilities in computer systems and networks. CVSS was commissioned in 2005 by the National Infrastructure Advisory Council (NIAC), a working group of the US Department of Homeland Security. It is currently maintained by the Forum of Incident Response and Security Teams.
The CVSS evaluates security vulnerabilities according to various criteria in order to enable a uniform assessment of these in different systems, to facilitate the prioritization of measures to remedy these vulnerabilities and to make them comparable with each other overall. CVSS evaluates vulnerabilities quantitatively on a scale from 0 to 10, with 10 being the highest criticality. In detail 8 different categories are included in the evaluation:
- Attack Vector (AV): Network, Adjacent, Local or Physical
- Attack Complexity (AC): Low or High
- Privileges Required (PR): None, Low or High
- User Interaction (UI): None or Required
- Scope (S): Unchanged or Changed
- Confidentiality Impact (C): None, Low or High
- Integrity Impact (I): None, Low or High
- Availability Impact (A): None, Low, or High
In the end, a criticality value of e.g. 4.2 or 5.3 is obtained according to mathematical calculation - and the various vulnerabilities can then be compared on the basis of these values or their remediation prioritized.
The CVSS is often requested by clients to have this comparability. In reality, however, the evaluation according to CVSS must be viewed critically. On the one hand, a subjective assessment still flows into the evaluation of the individual categories. On the other hand, the mathematical number at the end pretends to be granularly accurate, but has no significance at all (score of 4.1 vs 4.2 for example). In most cases, the clients then still carry out their own assessment, which leads the whole thing ad absurdum. We rather recommend carrying out a qualitative risk assessment right away in the first place.
binsec academy GmbH - Online IT Security Training with Practical Focus
binsec academy GmbH is provider of online IT security training, offering practical, lab-based courses for professionals. The academy provides hands-on training in areas such as penetration testing and secure software development. Participants gain practical experience through realistic lab environments, including simulations of company networks and applications. Courses are available in multiple programming languages and align with standards like OWASP Top 10 and PCI DSS. Upon successful completion, participants receive certifications such as the Binsec Academy Certified Pentest Professional (BACPP) and Binsec Academy Certified Secure Coding Professional (BACSCP), demonstrating their ability to identify and remediate security vulnerabilities.
Goto binsec acadmy GmbH

binsec GmbH – Experts in Penetration Testing
binsec GmbH is a German IT security company focused on professional penetration testing. With over 10 years of experience, the team conducts in-depth penetration tests on networks, web applications, APIs, and mobile apps. Certified experts systematically identify and document security vulnerabilities to support organizations in improving their security and meeting compliance requirements.
Goto binsec GmbH