← Security+ glossary

Vulnerability management

Common Vulnerability Scoring System (CVSS) CVSS

A standardized system that assigns vulnerabilities a severity score from 0 to 10 based on factors such as the complexity of exploitation and the impact on confidentiality, integrity and availability. A CVSS score is not the final word on patch priority because it does not take into account the organization's specific context, the criticality of the affected asset, or whether the vulnerability is actually exposed to an attacker.

All Security+ guides →

Related terms

Get CertOwl on the App Store

Free download · A+ and Network+ completely free
+ daily lessons, flashcards and full exam simulations