Accreditation
Standard
Formal independent recognition that a conformity-assessment body is competent to perform specified assessment or certification activities.
An open framework for describing the technical characteristics and severity of a software, hardware, or firmware vulnerability. A deeper explanation shows how CVSS fits into vulnerability management and risk, including the distinctions that prevent common confusion.
Definition
An open framework for describing the technical characteristics and severity of a software, hardware, or firmware vulnerability.
— Common Vulnerability Scoring System (CVSS)
In depth
An open framework for describing the technical characteristics and severity of a software, hardware, or firmware vulnerability. The fuller explanation connects CVSS with vulnerability management and risk and shows how the standard or reference term functions in practice.
CVSS converts defined vulnerability characteristics into a standardized vector and score. It helps different teams discuss technical severity consistently, but it does not know the value or exposure of a particular organization's assets.
Key points
CVSS represents vulnerability characteristics through named metrics. Base metrics describe intrinsic properties, threat metrics can reflect changing exploit conditions, environmental metrics adapt the analysis to a particular consumer, and supplemental metrics communicate additional context. The vector string is important because it preserves the assumptions behind a numeric result.
A high technical severity can matter less to an organization when the affected feature is absent or the asset is isolated; a more modest score can demand urgent attention when the service is exposed and business-critical. Asset value, reachability, compensating controls, exploitation evidence, and operational constraints belong in prioritization. CVSS complements those inputs. It also differs from CVE: CVE identifies a vulnerability, while CVSS describes severity characteristics.
Examples
Common misconceptions
Certification context
A reliable understanding of CVSS helps readers interpret technical documentation, exam objectives and system-design discussions with greater precision. The certification context connects the term with vulnerability management and risk while avoiding assumptions about a particular provider, exam or credential.
Why it matters
CVSS gives analysts a repeatable vocabulary for vulnerability characteristics while making the underlying assumptions inspectable in the vector.
In certification contexts
Candidates may interpret attack conditions, impact metrics, environmental adjustments, or explain why a severity score should not be treated as a complete risk rating.
Also known as
Topics
More terms
Common Vulnerability Scoring System (CVSS) is grouped with other standards and reference terms to support structured terminology browsing. Each result offers a concise definition and a deeper explanation for technical certification study and professional practice. The grouping reflects the kind of term rather than claiming that every item shares the same topic, provider or certification.
Standard
Formal independent recognition that a conformity-assessment body is competent to perform specified assessment or certification activities.
An IP addressing and routing approach that represents networks with variable-length prefixes instead of fixed address classes.
A public program and identifier system that gives disclosed cybersecurity vulnerabilities a common, globally recognizable reference.
Return to the glossary to search another acronym, concept, standard, technology or assessment term. Category and type filters make it easier to move from an unfamiliar phrase to a concise definition and a fuller practical explanation.