Triage BoardGet the app

Concept · Prioritization and mitigation

CVSS 4.0 vs 3.1: reading the vector

CVSS v4.0 keeps the 0–10 scale and the same severity bands as CVSS v3.1, but regroups the metrics: Base, Threat, Environmental and Supplemental replace v3.1's Base, Temporal and Environmental (FIRST specifications, checked October 2026). The CS0-004 objectives ask for "CVSS metrics" without naming a version, and a lot of prep material still teaches only v3.1, so expect to read both kinds of vector in prioritization and mitigation questions.

  • Exam code CS0-004
  • Tickets here 8

The metric groups side by side

Common Vulnerability Scoring System (CVSS) v3.1 and v4.0, per the FIRST specification documents
PointCVSS v3.1CVSS v4.0
Metric groups≠Base, Temporal, EnvironmentalBase, Threat, Environmental, Supplemental
Time-sensitive group≠Temporal: Exploit Code Maturity, Remediation Level, Report ConfidenceThreat: Exploit Maturity only
New Base metric≠NoneAttack Requirements (AT)
User Interaction values≠None, RequiredNone, Passive, Active
Scope≠Unchanged or ChangedRemoved: impact is split into the vulnerable system (VC, VI, VA) and subsequent systems (SC, SI, SA)
Extra context≠NoneSupplemental metrics such as Safety, Automatable and Recovery; they never change the score
Score labels≠Base, Temporal, Environmental scoreCVSS-B, CVSS-BT, CVSS-BE, CVSS-BTE
Severity bandsThe same five bands, listed belowThe same five bands, listed below

Rows marked ≠ are where the two differ.

One flaw, two vectors

cvssA fictional network-reachable flaw that needs no login, written in both versions
# CVE-20XX-0417 is a placeholder, not a real CVECVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A## S:U   gone in v4.0; impact now has VC/VI/VA and SC/SI/SA# AT:N  new in v4.0: no special condition on the target is needed# E:A   Threat metric Exploit Maturity = Attacked# line 3 is a CVSS-B vector, line 4 a CVSS-BT vector

Read the prefix first. CVSS:3.1/ and CVSS:4.0/ tell you which metric set the rest of the string uses.

The severity bands

Qualitative ratings, identical in v3.1 and v4.0 (FIRST, checked October 2026)
RatingScore rangeEdge to remember
None0.0Only an exact zero
Low0.1–3.93.9 is still Low
Medium4.0–6.96.9 is still Medium
High7.0–8.98.9 is still High
Critical9.0–10.09.0 starts Critical

Reading a vector on the exam

Walk the string left to right. The first four Base metrics describe how hard the flaw is to reach and trigger: Attack Vector (network, adjacent, local, physical), Attack Complexity (low or high), Privileges Required (none, low, high) and User Interaction. Each step away from the network, toward needing a login or a user's click, makes exploitation harder. The impact metrics come after.

Who fills in which group matters for scenario questions. The vendor or a vulnerability database publishes the Base metrics. Threat metrics come from intelligence about exploitation. Environmental metrics are yours: you raise or lower them to reflect how important the asset is and what controls already protect it. That is how CVSS takes your environment into account, and why a Base score alone can mislead.

Two v4.0 changes catch people who learned v3.1. Attack Requirements (AT) records conditions on the target that the attacker does not control, such as a race condition that has to be won or a non-default setting that has to be on; Attack Complexity now covers only what the attacker must do to get past protections like address randomization. User Interaction gains two levels: Passive, where the user only has to do something ordinary, like opening a page, and Active, where the user has to take a deliberate step, like dismissing a warning or running a file.

Threat metrics and EPSS can look like the same idea. Exploit Maturity records what is already known about exploitation, while EPSS predicts the chance of it in the next 30 days. The CVSS vs EPSS guide shows how the exam combines them.

No Temporal group in v4.0Trap

If an option asks you to adjust a v4.0 score with Temporal metrics, it is mixing versions. In v4.0 the Threat group takes over that role with a single metric, Exploit Maturity. Supplemental metrics add context for the reader, and no value you set there raises or lowers the number.

Decode the vector

Both CVSS versions turn up here. Confirm which one a vector string or score belongs to before you read anything into it.

Ticket 1 / 8

0 right

INC-001

A security analyst is assessing an application's vulnerability using the Common Vulnerability Scoring System (CVSS). The CVSS vector shows PR: H. What does the vector PR: H indicate to the security analyst?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. APhysical access is expressed by the Attack Vector metric as AV:P, while Privileges Required covers the access level the attacker needs.
  2. BLow privileges would be written PR:L.
  3. CCorrect: PR:H means the attacker must already hold high (administrative) privileges, and the metric means the same in CVSS v3.1 and v4.0.
  4. DRemote exploitation over a network is expressed by Attack Vector as AV:N, which PR does not capture.

INC-002

A cybersecurity analyst is assessing a network vulnerability and finds that it has a base score of 6.2 on the Common Vulnerability Scoring System (CVSS). What is the risk category of this vulnerability?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: on the CVSS qualitative severity scale, 4.0 to 6.9 is Medium, and the same bands apply to CVSS v3.1 and v4.0 scores.
  2. BLow covers 0.1 to 3.9, so 6.2 is above it.
  3. CCritical is reserved for 9.0 to 10.0.
  4. DHigh starts at 7.0, so 6.2 falls just short of it.

INC-003

A cybersecurity analyst is assessing the impact of a recently discovered vulnerability in a software application. Using the Common Vulnerability Scoring System (CVSS), this vulnerability has been assigned a score of 7.5. According to CVSS rankings, what is the severity level of this vulnerability?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: 7.5 falls in the High band (7.0–8.9), and CVSS v3.1 and v4.0 use the same severity bands.
  2. BMedium covers 4.0–6.9, so 7.5 is above it.
  3. CCritical starts at 9.0, so 7.5 does not qualify.
  4. DLow covers 0.1–3.9.

INC-004

While reviewing network security, a cybersecurity analyst needs to determine the CVSS base score for a newly discovered vulnerability. Which of the following data points is NOT necessary to calculate the CVSS base score?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AAttack vector is a base exploitability metric in both CVSS v3.1 and v4.0.
  2. BConfidentiality impact is a base metric (C in v3.1, VC/SC in v4.0).
  3. CPrivileges required is a base exploitability metric in both versions.
  4. DCorrect: patch history is not a base metric in either version, because base scores describe the vulnerability itself and ignore its remediation status.

INC-005

A vulnerability scanner reports three findings on production assets. Review the CVSS base scores and environmental attributes below. Which vulnerability requires the highest adjusted remediation priority?

Exhibit

FindingBase ScoreVectorAuthenticationCompensating Controls
A9.8NetworkNoneNone
B7.5NetworkRequiredWAF rules
C8.1AdjacentNoneNetwork segmentation

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AFinding C requires adjacent-network access and is behind segmentation, so its effective risk drops below its 8.1 base.
  2. BFinding B needs authentication and is behind WAF rules, so it is the most mitigated of the three.
  3. CCorrect: Finding A is network-reachable, needs no authentication and has no compensating controls, so its 9.8 stays the highest after environmental adjustment.
  4. DB is reduced by required authentication and WAF rules, so it does not match A's priority.

INC-006

Rank the following vulnerabilities by real-world exploitability from easiest to hardest to exploit, using the CVSS submetrics provided.

Exhibit

FindingAVACPRUI
ANLNN
BAHLR
CNLLN
DLLNN

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AD needs local access, which is harder than C's network access with low privileges, so D does not come second.
  2. BC needs low privileges, while A needs none, so A is easier and must come first.
  3. CB (adjacent network, high complexity, privileges and user interaction) is the hardest, so it cannot come first.
  4. DCorrect: A (network, low complexity, no privileges, no interaction) is easiest, then C (needs low privileges), then D (local access), then B; this uses CVSS v3.1 notation (UI:R), which v4.0 writes as UI:P or UI:A.

INC-007

In CVSS v4.0, which metric group takes the place of the Temporal metric group from CVSS v3.1?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: CVSS v4.0 replaces v3.1's Temporal group with the Threat group, built around Exploit Maturity.
  2. BSupplemental metrics are new in v4.0 and add context, but they are not the replacement for Temporal.
  3. CEnvironmental metrics exist in both v3.1 and v4.0; they did not replace Temporal.
  4. DExploitability metrics are part of the Base group in both versions, not a replacement for Temporal.

INC-008

A vendor publishes a CVSS v4.0 vector that includes Supplemental metrics such as Automatable (AU:Y) and Recovery. How do these metrics affect the CVSS-BTE score?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ANo fixed bonus exists; Supplemental values are reported alongside the score, not added to it.
  2. BEnvironmental metrics remain a separate group in v4.0 and still adjust the score for your environment.
  3. CSupplemental metrics never enter the score, whether or not Threat metrics are present.
  4. DCorrect: in CVSS v4.0, Supplemental metrics describe extra attributes and have no effect on the calculated score.

Shift tally

0 / 0

Sources

  1. FIRST, CVSS v4.0 specification (checked October 9, 2026)
  2. FIRST, CVSS v3.1 specification (checked October 9, 2026)
  3. CompTIA CySA+ CS0-004 exam objectives, version 2.0 (PDF) · objective 2.3, "CVSS metrics" (checked October 9, 2026)

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.