CVSS v4.0 Summary
CVSS v4.0 (Common Vulnerability Scoring System) is the latest version of the FIRST standard for assessing the severity of security vulnerabilities. It provides a more accurate and context-aware evaluation than CVSS v3.1.
Key Improvements over CVSS v3.1
Better separation between the vulnerability itself and the environment where it exists.
New metrics to better represent exploitability and real-world impact.
Replaces the traditional Temporal metrics with a simplified Threat metric.
Improves scoring consistency, reducing cases where different vulnerabilities received the same score.
Metric Groups
1. Base Metrics (Required)
Describe the intrinsic technical characteristics of the vulnerability.
They include:
Attack Vector (AV)
Attack Complexity (AC)
Attack Requirements (AT) (new)
Privileges Required (PR)
User Interaction (UI)
Vulnerable System Impact
Vulnerable Confidentiality (VC)
Vulnerable Integrity (VI)
Vulnerable Availability (VA)
Subsequent System Impact (new)
Subsequent Confidentiality (SC)
Subsequent Integrity (SI)
Subsequent Availability (SA)
2. Threat Metrics
Reflect the current exploitation status of the vulnerability.
Exploit Maturity (E)
This replaces most of the former Temporal metrics.
3. Environmental Metrics
Allow organizations to tailor the score to their specific environment.
They include security requirements for:
Confidentiality
Integrity
Availability
They also allow most Base metrics to be modified to reflect the organization's context.
4. Supplemental Metrics
Provide additional context without affecting the numerical score.
Examples include:
Safety
Automatable
Recovery
Value Density
Provider Urgency
Vulnerability Response Effort
New Metric: Attack Requirements (AT)
CVSS v4 distinguishes between:
Attack Complexity (AC): The technical difficulty of successfully exploiting the vulnerability.
Attack Requirements (AT): External conditions that must exist for the attack to succeed, such as a specific configuration or deployment scenario.
This separation provides a more accurate representation of exploitability.
Impact Split Across Systems
Unlike CVSS v3.1, which only evaluated the vulnerable system, CVSS v4 distinguishes between:
Vulnerable System: The system containing the vulnerability.
Subsequent System: Other systems affected as a consequence of exploiting the vulnerability.
This better models cloud environments, APIs, and supply chain attacks.
Scoring
CVSS scores range from 0.0 to 10.0:
Score Severity
0.0 None
0.1–3.9 Low
4.0–6.9 Medium
7.0–8.9 High
9.0–10.0 Critical
Example Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
When to Use Each Score
Base Score: Technical severity of the vulnerability.
Base + Threat: Severity considering the current exploitation status.
Environmental Score: Organization-specific priority based on the deployment environment.
Summary
CVSS v4.0 improves upon v3.1 by:
Separating technical complexity from attack prerequisites.
Distinguishing impacts on the vulnerable system and subsequent systems.
Introducing a more practical Threat metric.
Adding Supplemental metrics to provide operational context.
Offering greater flexibility for organization-specific risk assessment.
Overall, CVSS v4.0 provides a more accurate and actionable framework for vulnerability prioritization in modern IT environments.
As an additional commitment, since this is a paid application, the developer guarantees that the application will not include advertisements or promotional content that could interfere with the user experience. The paid model allows the application to maintain a clean, professional environment focused exclusively on vulnerability analysis and security assessment.
Common Vulnerability Scoring System v4