CVSS version 4.0 is current. It provides a technical language; a CVSS score is not business risk, exploit probability, or mandatory remediation priority.
CVSS 4.0 separates Base metrics from Threat and Environmental metrics, with Supplemental metrics carrying additional context without changing the score. Publishing the version and full vector preserves the assumptions behind a number and lets consumers adapt the assessment to their environment.
Key points
Base metricsThese describe intrinsic technical characteristics and impacts under the framework’s assumptions, independent of a particular consumer’s deployment and current threat information.
Contextual refinementThreat metrics can reflect exploitation maturity, while Environmental metrics allow a consumer to account for local controls, requirements, and modified technical conditions.
CommunicationUse the score with its vector, version, metric group, source, and assessment date; identical numbers can otherwise conceal materially different attack conditions and impacts.
Important limitationCVSS does not measure asset value, business consequence, exposure, likelihood of attack, remediation cost, or control effectiveness as a complete risk model, so score-only prioritization can misdirect effort.