TechKnowSurge
CompTIA CySA+ 2.3 CompTIA Security+ 4.3 NIST NICE K1076 CompTIA SecurityX 2.6 ISC2 CISSP 1.9 NIST NICE S0686 NIST CSF ID.RA-05
InteractiveSecurityFree

CVSS Score Estimator

Run the real CVSS v3.1 base formula by hand — impact sub-score, exploitability sub-score, the Scope Changed branch and CVSS’s own Roundup — on the vectors a scanner actually reports, then read the severity rating off the score.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

CVSS v3.1 turns eight base metrics into one number between 0.0 and 10.0, and this drill makes you produce that number rather than read it off a scanner. Every item hands you a scenario, the CVSS vector string that describes it, the numeric weight each of its metrics carries, and the formula branch that applies — then takes the base score to one decimal place, or the severity rating, typed and graded exactly. The vectors are the ones the job actually produces: unauthenticated remote code execution at 9.8, memory disclosure at 7.5, local privilege escalation at 7.8, reflected cross-site scripting at 6.1, an evil-maid disk read at 4.6. Four of them have a CHANGED scope, which is where most hand-scored CVSS goes wrong: it uses a different impact formula, it raises the Privileges Required weights (Low becomes 0.68, not 0.62), and it multiplies the total by 1.08. Three items isolate one step so the arithmetic can be practised without the whole chain, and five drill the severity bands at their boundaries, because 3.9 and 4.0 are one tenth and two different remediation queues. Roundup is drilled deliberately: it takes a score UP to the next tenth, never to the nearest one, and six of the answers in this pool differ from what ordinary rounding would give. A miss shows the full derivation — ISS, impact, exploitability, the sum and the roundup — not just the number.

What you'll learn

Aligned to

CompTIA CySA+
2.3 Given a scenario, analyze data to prioritize vulnerabilities.
CompTIA Security+
4.3 Explain various activities associated with vulnerability management.
NIST NICE
K1076 Knowledge of risk scoring principles and practices
S0686 Skill in performing risk assessments
CompTIA SecurityX
2.6 Explain how threat and vulnerability management techniques are used in the enterprise.
ISC2 CISSP
1.9 Understand and apply risk management concepts
NIST CSF
ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization.

Key terms

Common Vulnerability Scoring System
CVSS
Common Vulnerability Scoring System is an open industry standard that provides a numerical score from 0 to 10 representing the severity of a vulnerability, enabling organizations to prioritize remediation efforts based on base, temporal, and environmental metrics.
Attack Vector
The specific path or method a threat actor uses to gain unauthorized access to a system or network, such as a phishing email, an unpatched vulnerability, or a misconfigured network port.
Exploitability
A measure of how easily a vulnerability can be leveraged by an attacker to gain unauthorized access to an asset.
Confidentiality
The principle that information is accessible only to those authorized to access it.
Integrity
The assurance that data has not been tampered with and remains accurate and complete.
Availability
The assurance that systems and data are accessible and operational when needed by authorized users.
Common Vulnerabilities and Exposures
CVE
Common Vulnerabilities and Exposures is a publicly maintained dictionary that assigns unique identifiers to known software and hardware vulnerabilities, providing a common reference point for vulnerability tracking, disclosure, and remediation.
National Vulnerability Database
NVD
The National Vulnerability Database is NIST's repository of vulnerability information enriched with CVSS scores, CPE identifiers, and remediation data, serving as the authoritative source for tracking and prioritizing known CVEs.

Topics

Interactive Calculation Cvss Vulnerability Scoring Vulnerability Management Risk Prioritization Base Score Severity Rating

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →