Skip to main content

NOTICE: Due to a lapse in annual appropriations, most of this website is not being updated. Learn more.

Form submissions will still be accepted but will not receive responses at this time. Sections of this site for programs using non-appropriated funds (such as NVLAP) or those that are excepted from the shutdown (such as CHIPS and NVD) will continue to be updated.

U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Improving the Common Vulnerability Scoring System

Published

Author(s)

Peter M. Mell, Karen A. Scarfone

Abstract

The Common Vulnerability Scoring System is an emerging standard for scoring the impact of vulnerabilities. This paper presents the results of our analysis of the scoring system and the results of our experiment scoring a large set of vulnerabilities using the standard. While the scoring system was found to be useful, it contains a variety of deficiencies that limit its ability to measure the impact of vulnerabilities. We demonstrate how these deficiencies could be addressed in subsequent versions of the standards and how these changes can be backwards-compatible with existing scoring efforts.
Citation
Institution of Engineering and Technology (IET) Information Security

Citation

Mell, P. and Scarfone, K. (2007), Improving the Common Vulnerability Scoring System, Institution of Engineering and Technology (IET) Information Security, [online], https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=51124 (Accessed October 17, 2025)

Issues

If you have any questions about this publication or are having problems accessing it, please contact [email protected].

Created September 28, 2007, Updated February 17, 2017
Was this page helpful?