Skip to main content
Calcimator

Vulnerability CVSS Score Calculator

Calculate CVSS v3.1 Base Score from the 8 base metrics (attack vector, complexity, privileges, user interaction, scope, and CIA impact).

About this calculator

This implements the official CVSS v3.1 Base Score formula published by FIRST.Org, Inc. in its "Common Vulnerability Scoring System v3.1: Specification Document," not an approximation. Four exploitability metrics — attack vector, attack complexity, privileges required, and user interaction — each carry a FIRST-assigned numeric weight, and their product times a constant (8.22) produces the exploitability sub-score: how easy the flaw is to reach and trigger. Three impact metrics — confidentiality, integrity, and availability, each None/Low/High — combine into an impact sub-score via 1 minus the product of their complements, meaning impacts don't simply add: two "High" impacts push the sub-score toward its ceiling faster than the numbers might suggest. Scope is the subtlest input: "Changed" means a successful exploit can affect resources beyond the vulnerable component's own security authority (a container escape reaching the host, for instance), and it switches both the privileges-required weighting and the entire impact formula to a different, more aggressive curve.

Base score is exploitability plus impact, rounded up to one decimal place (CVSS always rounds up, never to nearest — a 7.01 becomes 7.1, not 7.0), then mapped to a severity band: None, Low (0.1-3.9), Medium (4.0-6.9), High (7.0-8.9), or Critical (9.0-10.0). The calculator also suggests a remediation SLA per band (24 hours for Critical down to 30 days for Low) as a practical starting point — treat it as a baseline to tune against your own risk tolerance and compensating controls, not a universal deadline. This is Base Score only; it doesn't account for Temporal or Environmental metrics that can shift real-world urgency.

Inputs

Results

CVSS Base Score

9.8

Severity (0-4)

4

Exploitability sub-score3.9
Impact sub-score5.9
Recommended SLA (hours)24

Figures current as of 2019. Source: FIRST.Org, Inc., "Common Vulnerability Scoring System v3.1: Specification Document"

How to Use This Calculator
  1. Select Attack Vector from the dropdown (Network, Adjacent, Local, or Physical) -- network-accessible vulnerabilities score highest.
  2. Set Attack Complexity (0=Low, 1=High), Privileges Required (0=None, 1=Low, 2=High), and User Interaction (0=None, 1=Required).
  3. Set Scope (0=Unchanged, 1=Changed) and Confidentiality, Integrity, and Availability Impact.
  4. Review CVSS Base Score (0-10), Exploitability score, Impact score, and severity rating.
  5. Prioritize Critical (9.0-10) and High (7.0-8.9) findings for immediate remediation.

What each input means

Attack Vector
How the vulnerability can be reached by an attacker.
Attack Complexity (0-1)
0 = Low (no special conditions), 1 = High (requires specific configuration or race condition).
Privileges Required (0-2)
0 = None (unauthenticated), 1 = Low (basic user), 2 = High (admin/root).
User Interaction (0-1)
0 = None (no user action needed), 1 = Required (victim must click link, open file, etc.).
Scope (0-1)
0 = Unchanged (impact limited to vulnerable component), 1 = Changed (can affect other components).
Confidentiality Impact (0-2)
0 = None, 1 = Low (some data exposed), 2 = High (all data exposed).
Integrity Impact (0-2)
0 = None, 1 = Low (some data modifiable), 2 = High (all data modifiable).
Availability Impact (0-2)
0 = None, 1 = Low (degraded performance), 2 = High (complete denial of service).

What each result means

CVSS Base Score
CVSS v3.1 Base Score (0.0-10.0) per FIRST.org specification.
Exploitability sub-score
How easy the vulnerability is to exploit (0-10).
Impact sub-score
Consequence of successful exploitation (0-10).
Severity (0-4)
0 = None, 1 = Low (0.1-3.9), 2 = Medium (4.0-6.9), 3 = High (7.0-8.9), 4 = Critical (9.0-10.0).
Recommended SLA (hours)
Typical remediation SLA: Critical = 24h, High = 48h, Medium = 7 days, Low = 30 days.

How this is calculated

Worked example, using the default values

  1. Identify Input Parameters
    4 parameters
    Attack Vector (0-3) = 0, Attack Complexity (0-1) = 0, Privileges Required (0-2) = 0, User Interaction (0-1) = 0 = 8 input(s) provided
  2. Calculate CVSS Base Score
    CVSS Base Score
    9.8 = 9.8
  3. Calculate Severity
    Severity
    4 = 4
  4. Calculate Exploitability sub-score
    Exploitability sub-score = 8.22 * avVal * acVal * prVal * uiVal
    3.9 = 3.9
  5. Calculate Impact sub-score
    Impact sub-score = Math
    5.9 = 5.9

Figures and sources

Engine last updated . Checked against 3 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.

Frequently Asked Questions

Why does changing Scope affect Privileges Required, not just the impact calculation?

Scope Changed means the vulnerable component's security authority is being bypassed to affect a different component, so FIRST's specification treats privileges required as easier to leverage in that scenario -- the weights for Low and High privileges are higher under Scope Changed (0.68 and 0.50) than Scope Unchanged (0.62 and 0.27). It also swaps in an entirely different impact formula with different constants (7.52 and a subtracted power term instead of a flat 6.42 multiplier), which is why Scope Changed vulnerabilities can score noticeably higher than Scope Unchanged ones with identical CIA impact settings.

Why did my score come out lower than I expected given three High impacts?

The impact sub-score combines Confidentiality, Integrity, and Availability using 1 minus the product of their complements, not a simple sum or average. Three High impacts (each weighted 0.56) produce 1 - (1-0.56)^3 = 0.915, which is close to but not the same as adding them -- and one High plus two None impacts produces only 0.56, since None contributes a weight of zero and doesn't average things upward.

Why does the calculator round 7.01 up to 7.1 instead of 7.0?

CVSS v3.1's official specification always rounds the base score up to the nearest tenth, never to the nearest tenth -- this calculator implements that with Math.ceil rather than Math.round, matching the FIRST.org reference formula exactly. It's a deliberate scoring convention meant to avoid ever underrepresenting severity through rounding.

Is the remediation SLA this calculator suggests a compliance requirement?

No -- it's a practical starting point (24 hours for Critical down to 30 days for Low) based on common industry practice, not a mandated standard from FIRST.org or any regulator. Your actual SLA should also weigh compensating controls, exploit availability, and asset criticality, none of which the CVSS Base Score alone captures since it deliberately excludes Temporal and Environmental metrics.

The questions that sit next to this one — chosen by subject, including calculators filed under a different category.

More in Technology & Computing.