BASE METRICS Β· CONTEXT Β· PRIORITY

CVSS 3.1 Severity Calculator

Calculate a CVSS 3.1 base score, then document the real attack path, affected assets, and business impact before assigning priority.

CVSS 3.1 BASE METRICS

Score the attack path you proved

Use the evidence from your engagement. Do not inflate metrics to force a severity label.

RESULT

0.0None

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

  • Write the concrete path that justifies each metric.
  • Separate CVSS from business priority and program severity.
  • Link evidence from your report template before you publish.

Open report templates β†’

Severity writing tips

Is a high CVSS always a high-priority fix?

No. Exploitability, asset value, data sensitivity, blast radius, and compensating controls can change priority.

What should accompany the score?

Affected asset, prerequisites, reproduction steps, evidence, security boundary broken, and a root-cause fix.