NOTICE: Due to a lapse in annual appropriations, most of this website is not being updated. Learn more.
Form submissions will still be accepted but will not receive responses at this time. Sections of this site for programs using non-appropriated funds (such as NVLAP) or those that are excepted from the shutdown (such as CHIPS and NVD) will continue to be updated.
An official website of the United States government
Here’s how you know
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (
) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
A Complete Guide to the Common Vulnerability Scoring System Version 2.0
Published
Author(s)
Peter M. Mell, Karen A. Scarfone, Sasha Romanosky
Abstract
The Common Vulnerability Scoring System (CVSS) provides an open framework for communicating the characteristics and impacts of IT vulnerabilities. CVSS consists of three groups: Base, Temporal and Environmental. Each group produces a numeric score ranging from 0 to 10, and a Vector, a compressed textual representation that reflects the values used to derive the score. The Base group represents the intrinsic qualities of a vulnerability. The Temporal group reflects the characteristics of a vulnerability that change over time. The Environmental group represents the characteristics of a vulnerability that are unique to any user¿s environment. CVSS enables IT managers, vulnerability bulletin providers, security vendors, application vendors and researchers to all benefit by adopting this common language of scoring IT vulnerabilities. This guide defines CVSS version 2 and explains how its metrics, equations, and scores can be used.
Mell, P.
, Scarfone, K.
and Romanosky, S.
(2007),
A Complete Guide to the Common Vulnerability Scoring System Version 2.0, FIRST, [online], https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=51198, http://www.first.org/cvss/cvss-guide.pdf
(Accessed October 6, 2025)