Home > Glossary > CompTIA PenTest+ > Common Vulnerability Scoring System (CVSS)

📖 What is Common Vulnerability Scoring System (CVSS)?

The Common Vulnerability Scoring System (CVSS) is a standardized framework used to rate the severity of software vulnerabilities. It provides a numerical score reflecting the ease of exploitation and the potential impact on confidentiality, integrity, and availability.

🥋 Sensei Says:

"Pay attention to the difference between Base, Temporal, and Environmental scores; the Base score is the most common metric you will encounter in vulnerability reports."

📚 Certification: CompTIA PenTest+ (PT0-002)

🔑 What are the Key Concepts of Common Vulnerability Scoring System (CVSS)?

  • The Base Score represents intrinsic qualities of a vulnerability, including attack vector, complexity, and the impact on confidentiality, integrity, and availability.
  • Temporal Scores account for factors that change over time, such as the availability of an official patch or the maturity of public exploit code.
  • Environmental Scores allow organizations to customize the severity based on the importance of the affected asset and the presence of existing security controls.
  • The CIA triad serves as the foundation for impact metrics, measuring how much a vulnerability compromises the secrecy, accuracy, or accessibility of data.
  • Numerical score ranges categorize vulnerabilities into Low, Medium, High, and Critical levels, which penetration testers use to prioritize remediation efforts.

🎯 How does Common Vulnerability Scoring System (CVSS) appear on the PT0-002 Exam?

You may be asked to prioritize a list of discovered vulnerabilities by comparing their Base scores to determine which pose the highest immediate risk to the organization.

A scenario might describe a critical vulnerability on a decommissioned or isolated server; you must identify how the Environmental score reduces the actual risk level.

Expect questions requiring you to analyze a CVSS vector string to determine if a vulnerability requires user interaction or specific privileges to be successfully exploited.

❓ Frequently Asked Questions

Why should a penetration tester consider the Environmental score instead of just the Base score?

The Base score represents a vulnerability in a vacuum. The Environmental score allows a tester to adjust the severity based on the asset's actual business value and the specific mitigating controls present in the target environment.


What is the significance of the 'Scope' metric introduced in CVSS v3?

The Scope metric determines if a vulnerability in one component can impact resources in a different security authority, such as a virtual machine escape affecting the underlying hypervisor.

Related Terms from CompTIA PenTest+

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand Common Vulnerability Scoring System (CVSS)? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium