CVSS
FIRSTCommon Vulnerability Scoring System
- Answers
- How severe is this vulnerability in the abstract?
- Output
- A 0.0–10.0 score
- Scope
- Software vulnerabilities with a CVE
What it does well
Universally understood, vendor-independent, and present in essentially every scanner's output. The base score is a genuinely useful shorthand for intrinsic severity, and the temporal and environmental metrics — which almost nobody uses — were designed to address exactly the contextual gap people complain about.
Where it stops
The base score describes the vulnerability, not your exposure to it. It cannot express whether the component is reachable, whether anyone is exploiting it, or what data sits behind it. Because most organisations use base scores alone, prioritising by CVSS means prioritising by a number that is identical for every organisation on earth.
Using it with Beacon
Beacon uses CVSS as one input to question 2. A high score raises the likelihood that exploitation grants meaningful access, but it never determines the tier by itself.