9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability Metrics
Scope
Impact Metrics
About CVSS v3.1
The Common Vulnerability Scoring System (CVSS) v3.1 is the industry-standard framework for communicating the severity of software vulnerabilities. The Base score (0–10) reflects intrinsic characteristics that are constant over time: how exploitable the vulnerability is, and the impact on confidentiality, integrity and availability. CISOs use base scores to prioritise remediation, Critical (9.0–10) typically requires emergency patching, High (7.0–8.9) within days, Medium (4.0–6.9) within weeks. Always consider environmental and temporal context before using base scores alone to drive patch scheduling.