Build a CVSS 2.0 vector and get the base score, severity rating, and a visual metric breakdown instantly, with results that match the official FIRST.org reference calculator.
Choose a value for each metric. The score updates in real time.
Optional. Leave a metric “Not Defined” to exclude it. When any temporal or environmental metric is set, the score reflects that higher level.
A visual breakdown of the selected base metrics. Drag a point or tap a grey marker to explore how each metric shifts the score.
Every base metric, plus any temporal/threat or environmental metric you set, and how it is contributing to the base score.
Network
This metric reflects how the vulnerability is exploited. The more remote an attacker can be to attack a host, the greater the vulnerability score.
Low
This metric measures the complexity of the attack required to exploit the vulnerability once an attacker has gained access to the target system.
None
This metric measures the number of times an attacker must authenticate to a target in order to exploit a vulnerability. This metric does not gauge the strength or complexity of the authentication process.
Complete
This metric measures the impact on confidentiality of a successfully exploited vulnerability. Confidentiality refers to limiting information access and disclosure to only authorized users.
Complete
This metric measures the impact to integrity of a successfully exploited vulnerability. Integrity refers to the trustworthiness and guaranteed veracity of information.
Complete
This metric measures the impact to availability of a successfully exploited vulnerability. Availability refers to the accessibility of information resources.
How the CVSS 2.0 base score is built from its metrics.
CVSS 2.0 is the legacy version of the Common Vulnerability Scoring System, used in older advisories and historical National Vulnerability Database entries. It has a simpler base metric set (Access Vector, Access Complexity, Authentication, and Confidentiality, Integrity, and Availability impact) and a three-band severity scale with no Critical rating.
Select a value for each base metric below to build a CVSS 2.0 vector string and compute the base score in real time. The score, severity rating, and canonical vector string update immediately, and the vector can be copied, shared, or pasted back in to reproduce a score exactly.
Common questions about CVSS 2.0 scoring.