CVSS (Common Vulnerability Scoring System)

PCIComplianceHubLast updated

An open standard, maintained by FIRST, that scores the severity of a vulnerability from 0.0 to 10.0. PCI DSS uses it as an input to the risk ranking required for vulnerability management, and the ASV Program Guide uses it directly: on an external scan, a vulnerability with a CVSS base score of 4.0 or above is normally an automatic failing condition. A score alone is not a risk ranking, though. An organization is expected to weigh the score against its own environment and record how it reached its conclusion.