Direct Entry Guided Rubric

A guided questionnaire for CVSS v4.0's Base Metrics as transcribed from FIRST.org's CVSS v4.0 User Guide.

Findings are kept only in your current browser session and are cleared when it ends — nothing is saved to a database or shared with anyone.

Answer each question below — its metric value fills in automatically once resolved, and the submit button unlocks once all 11 are set. The three Subsequent System impact metrics default to None; work through their questions only if this vulnerability also affects systems beyond the vulnerable component. Use the “i” tooltips next to a question for extra guidance.

0 of 11 metrics answered

Leave as-is to auto-assign the next ID, or type your own.
Prefills the description below. Metrics still come from the questions below, not NVD.
Have a CVSS 3.1 score for this vulnerability but no 4.0 score? Paste its vector here — no CVE required, and it auto-fills from an NVD lookup above when available. There's no official FIRST.org/NVD conversion between versions, so this only fills in what the metric definitions make unambiguous; the rest is left for the questions below.
Type a description above to enable this. AI-generated suggestion, not authoritative — review before relying on it.

Exploitability Metrics

Attack Vector Not started
Attack Complexity Not started
Attack Requirements Not started
Privileges Required Not started
User Interaction Not started

Vulnerable System Impact

Confidentiality (Vulnerable System) Not started
Integrity (Vulnerable System) Not started
Availability (Vulnerable System) Not started

Subsequent System Impact

Confidentiality (Subsequent System) Not started
Integrity (Subsequent System) Not started
Availability (Subsequent System) Not started