What is CVSS (Common Vulnerability Scoring System)?

The Common Vulnerability Scoring System (CVSS) is a standard for assessing the criticality of security vulnerabilities in computer systems and networks. CVSS was commissioned in 2005 by the National Infrastructure Advisory Council (NIAC), a working group of the US Department of Homeland Security. It is currently maintained by the Forum of Incident Response and Security Teams.

The CVSS evaluates security vulnerabilities according to various criteria in order to enable a uniform assessment of these in different systems, to facilitate the prioritization of measures to remedy these vulnerabilities and to make them comparable with each other overall. CVSS evaluates vulnerabilities quantitatively on a scale from 0 to 10, with 10 being the highest criticality. In detail 8 different categories are included in the evaluation:

  • Attack Vector (AV): Network, Adjacent, Local or Physical
  • Attack Complexity (AC): Low or High
  • Privileges Required (PR): None, Low or High
  • User Interaction (UI): None or Required
  • Scope (S): Unchanged or Changed
  • Confidentiality Impact (C): None, Low or High
  • Integrity Impact (I): None, Low or High
  • Availability Impact (A): None, Low, or High

In the end, a criticality value of e.g. 4.2 or 5.3 is obtained according to mathematical calculation - and the various vulnerabilities can then be compared on the basis of these values or their remediation prioritized.

The CVSS is often requested by clients to have this comparability. In reality, however, the evaluation according to CVSS must be viewed critically. On the one hand, a subjective assessment still flows into the evaluation of the individual categories. On the other hand, the mathematical number at the end pretends to be granularly accurate, but has no significance at all (score of 4.1 vs 4.2 for example). In most cases, the clients then still carry out their own assessment, which leads the whole thing ad absurdum. We rather recommend carrying out a qualitative risk assessment right away in the first place.

binsec academy GmbH – Advanced Pentest Training Lab

binsec academy GmbH operates the Pentest Training Lab, a highly practical online platform dedicated to real penetration testing. Simulating complex corporate networks and advanced real-world attack scenarios within isolated lab environments, it is engineered to sharpen the skills of aspiring and professional penetration testers. Upon conquering our rigorous, fully practical examination, participants earn the distinguished Binsec Academy Certified Pentest Professional (BACPP) designation — proving their technical capability to methodically uncover and evaluate vulnerabilities in modern IT infrastructures.

Explore the Pentest Training Lab

binsec GmbH – Experts in Penetration Testing

As the operative pentesting core of the binsec group, binsec GmbH has provided high-end, human-led penetration testing since 2013. Rejecting automated scans, our permanently employed, certified senior pentest experts deliver manual deep-dive assessments of web applications, APIs, mobile apps, complex network infrastructures, cloud environments, and advanced red team simulations. Specializing in high-regulation sectors like Payment, Banking, and Healthcare, we provide clear risk evaluations and actionable reports to effectively assess your business-critical systems.

Get Manual Expert Penetration Testing Services

Contact

binsec GmbH
Clemensstraße 6-8
60487 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorized Officer: Dominik Sauer, Florian Zavatzki
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808