What Is CVSS?
The Common Vulnerability Scoring System (aka CVSS Scores) provides a numerical (0-10) representation of the severity of an information security vulnerability.
CVSS scores are commonly used by infosec teams as part of a vulnerability management program to provide a point of comparison between vulnerabilities and to prioritize remediation of vulnerabilities.CVSS is an open framework maintained by the Forum of Incident Response and Security Teams (FIRST), a US-based nonprofit with over 500 member organizations globally. While rating vulnerabilities based on an open, standardized methodology is powerful, it’s also important to recognize the drawbacks and limitations of CVSS in order to ensure that it’s being applied appropriately in your organization.