Skip to content

CVSS Scoring ​

Hashiro integrates the Common Vulnerability Scoring System v3.1 (CVSS) into every security finding. CVSS provides a standardized method for rating vulnerability severity and communicating risk.

CVSS score calculator

Screenshots use fictional demonstration data.

Score Calculator ​

The built-in calculator lets you set each vector component and automatically computes the overall score.

Exploitability Metrics ​

MetricValuesDescription
Attack Vector (AV)Network, Adjacent, Local, PhysicalHow the vulnerability is exploited
Attack Complexity (AC)Low, HighConditions beyond the attacker's control
Privileges Required (PR)None, Low, HighAccess level needed before exploitation
User Interaction (UI)None, RequiredWhether a user must take action

Scope ​

MetricValuesDescription
Scope (S)Unchanged, ChangedWhether exploitation impacts resources beyond the vulnerable component

Impact Metrics ​

MetricValuesDescription
Confidentiality (C)None, Low, HighImpact on information disclosure
Integrity (I)None, Low, HighImpact on data modification
Availability (A)None, Low, HighImpact on service availability

Severity Classification ​

The CVSS score maps to a severity level:

Score RangeSeverity
9.0 - 10.0Critical
7.0 - 8.9High
4.0 - 6.9Medium
0.1 - 3.9Low
0.0Informative

Vector String ​

Each assessment produces a vector string encoding all metrics in a compact format:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

This string is stored with the finding and included in reports.

How CVSS Is Used in Hashiro ​

  • Prioritization: findings are ranked by score in project views and dashboards
  • Reporting: scores appear alongside each finding in PDF reports
  • Dashboard metrics: severity breakdowns derive from CVSS classifications
  • Remediation planning: the effort matrix combines severity with remediation complexity

Hashiro. Continuous Threat Exposure Management.