Build a CVSS 3.0 vector and get the base score, severity rating, and a visual metric breakdown instantly, with results that match the official FIRST.org reference calculator.
Choose a value for each metric. The score updates in real time.
Optional. Leave a metric “Not Defined” to exclude it. When any temporal or environmental metric is set, the score reflects that higher level.
A visual breakdown of the selected base metrics. Drag a point or tap a grey marker to explore how each metric shifts the score.
Every base metric, plus any temporal/threat or environmental metric you set, and how it is contributing to the base score.
Network
This metric reflects the context by which vulnerability exploitation is possible. This metric value (and consequently the Base score) will be larger the more remote (logically, and physically) an attacker can be in order to exploit the vulnerable component.
Low
This metric describes the conditions beyond the attacker's control that must exist in order to exploit the vulnerability. As described below, such conditions may require the collection of more information about the target, the presence of certain system configuration settings, or computational exceptions.
None
This metric describes the level of privileges an attacker must possess before successfully exploiting the vulnerability. This metric is greatest if no privileges are required.
None
This metric captures the requirement for a user, other than the attacker, to participate in the successful compromise of the vulnerable component. This metric determines whether the vulnerability can be exploited solely at the will of the attacker, or whether a separate user (or user-initiated process) must participate in some manner.
Unchanged
Formally, Scope refers to the collection of privileges defined by a computing authority when granting access to computing resources. When a vulnerability in one component is able to affect resources governed by another authorization scope, a Scope change has occurred.
High
This metric measures the impact to the confidentiality of the information resources managed by a software component due to a successfully exploited vulnerability. Confidentiality refers to limiting information access and disclosure to only authorized users.
High
This metric measures the impact to integrity of a successfully exploited vulnerability. Integrity refers to the trustworthiness and veracity of information.
High
This metric measures the impact to the availability of the impacted component resulting from a successfully exploited vulnerability. This metric refers to the loss of availability of the impacted component itself, such as a networked service.
How the CVSS 3.0 base score is built from its metrics.
CVSS 3.0 is the first release of the 3.x series of the Common Vulnerability Scoring System, introduced by FIRST.org in 2015. It uses the same base metrics as 3.1, including the Scope metric, but its scoring formula rounds slightly differently, so 3.0 scores are reproduced with a dedicated calculator.
Select a value for each base metric below to build a CVSS 3.0 vector string and compute the base score in real time. The score, severity rating, and canonical vector string update immediately, and the vector can be copied, shared, or pasted back in to reproduce a score exactly.
Common questions about CVSS 3.0 scoring.