Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Common Vulnerability Scoring System (CVSS)

Also known as: CVSS

German: Common Vulnerability Scoring System (CVSS)

The Common Vulnerability Scoring System (CVSS) is an open framework maintained by FIRST for rating the severity of software vulnerabilities on a scale from 0.0 to 10.0, based on metrics such as attack vector, complexity, required privileges and impact on confidentiality, integrity and availability.

  • OT security
  • Standards

In one sentence

CVSS is an open framework by FIRST that rates the severity of vulnerabilities from 0.0 to 10.0 based on exploitability and impact metrics.

Example

A vulnerability in a PLC web server has a CVSS base score of 9.8 (Critical), but the operator lowers its priority because the web server is disabled and the PLC sits in an isolated zone.

Explained in context

Context cards connect this term with others to answer one question. Also in British English and German.

How it applies

  • Engineering: Product suppliers include a CVSS vector and score in their Security advisory documents. CVSS version 3.1 is still widespread; version 4.0 was published in 2023 and adds metric groups for threat and supplemental information.
  • Operation: The base score describes the vulnerability in general. Operators should adjust priority to their environment, for example exposure, compensating controls and the consequences for the process. CVSS does not measure safety impact on a machine.
  • Maintenance: Scores help triage many findings, but a high score on an unreachable device may matter less than a medium score on an internet-facing gateway.
  • Documentation: When writing advisories or release notes, give the CVSS version together with the vector string, not just the number, so readers can see how the score was derived.

CVSS vs. risk

CVSS rates severity, not risk. Risk for a plant also depends on likelihood of attack, exposure and consequences, which the Security risk assessment covers. In machine safety, Risk estimation follows its own method under ISO 12100.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: FIRST, Common Vulnerability Scoring System specification (versions 3.1 and 4.0)

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!