Glossary · OT cybersecurity
Common Vulnerability Scoring System (CVSS)
Also known as: CVSS
German: Common Vulnerability Scoring System (CVSS)
The Common Vulnerability Scoring System (CVSS) is an open framework maintained by FIRST for rating the severity of software vulnerabilities on a scale from 0.0 to 10.0, based on metrics such as attack vector, complexity, required privileges and impact on confidentiality, integrity and availability.
- OT security
- Standards
In one sentence
CVSS is an open framework by FIRST that rates the severity of vulnerabilities from 0.0 to 10.0 based on exploitability and impact metrics.
Example
A vulnerability in a PLC web server has a CVSS base score of 9.8 (Critical), but the operator lowers its priority because the web server is disabled and the PLC sits in an isolated zone.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
How it applies
- Engineering: Product suppliers include a CVSS vector and score in their Security advisory documents. CVSS version 3.1 is still widespread; version 4.0 was published in 2023 and adds metric groups for threat and supplemental information.
- Operation: The base score describes the vulnerability in general. Operators should adjust priority to their environment, for example exposure, compensating controls and the consequences for the process. CVSS does not measure safety impact on a machine.
- Maintenance: Scores help triage many findings, but a high score on an unreachable device may matter less than a medium score on an internet-facing gateway.
- Documentation: When writing advisories or release notes, give the CVSS version together with the vector string, not just the number, so readers can see how the score was derived.
CVSS vs. risk
CVSS rates severity, not risk. Risk for a plant also depends on likelihood of attack, exposure and consequences, which the Security risk assessment covers. In machine safety, Risk estimation follows its own method under ISO 12100.