AI Offensive Security Certification
AU · CA · NZ · UK · US
StrikeOps Academy
CurriculumPathwaysCertificationsPricing
Search/Start learning
CurriculumREF · Reference LibrarySeverity and CVSS rubric
REFReference Library

Severity and CVSS rubric

The calibration reference for rating findings: what each severity level means, how to use CVSS without being ruled by it, and how to turn a score into a risk.

Foundational3 min readfoundation streamUpdated Sat Aug 01 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
On this page
  • The five severity levels
  • Using CVSS (v4.0) well
  • Likelihood times impact (for the matrix)
  • Writing the impact statement
  • Status, for completeness
  • Related reading

Learning objectives

  • Assign a consistent severity level to a finding based on risk, not raw score
  • Use the three CVSS metric groups and tailor a score to the client's context
  • Write an impact statement that makes the risk legible to a non-specialist

A practical reference for rating findings consistently. This is the lookup you keep open while writing findings: how the levels are defined, how to use CVSS without being ruled by it, and how to turn a score into a risk a client can act on.

The five severity levels

Calibrate to risk (likelihood times impact in this environment), not raw CVSS.

SeverityMeansTypical examplesAction
CriticalDirect path to major impact; exploit is realistic nowUnauthenticated RCE on a sensitive system; a full domain-compromise chain; mass PII exposureFix immediately
HighSerious, exploitable, meaningful impactPrivilege escalation; significant access-control failure; credential exposureFix soon
MediumExploitable under conditions, or moderate impactIssues needing a precondition; info disclosure that enables a chainPlan remediation
LowLimited impact or hard to exploitHardening gaps, minor misconfig, low-value disclosureFix opportunistically
InfoNo direct riskObservations, defence-in-depth notes, positive validationsAwareness

The chain rule. Rate a finding for what it enables, not just what it is alone. An audit-log leak looks low, until it hands an attacker the identifier that completes a privilege-escalation chain. Score the role it plays.

Using CVSS (v4.0) well

CVSS gives a defensible, comparable 0 to 10 score. Record both the vector and the score on every finding. Its metric groups:

  • Base covers intrinsic properties: attack vector, complexity, privileges required, user interaction, and impact to confidentiality, integrity and availability. A property of the vulnerability.
  • Threat asks whether there is a known or weaponised exploit. It raises urgency.
  • Environmental covers your client's context: how important is this specific asset? This is where a generic score becomes a real risk, so do not leave it on the table.

Rough score-to-severity banding (a guide, not a law):

CVSSBand
9.0 to 10.0Critical
7.0 to 8.9High
4.0 to 6.9Medium
0.1 to 3.9Low
0.0Info

CVSS is a yardstick, not an oracle. A 9.8 on an isolated, dataless, decommissioned box may be a low risk; a 6.5 on the one server holding every customer record may be a high risk. Let business impact override the band when they disagree, and say why.

Likelihood times impact (for the matrix)

For communicating to non-specialists, a matrix often beats a decimal. A finding can carry a likelihood alongside severity to render a risk matrix:

Low impactMedium impactHigh impact
LikelyMediumHighCritical
PossibleLowMediumHigh
UnlikelyLowLowMedium
  • Likelihood is feasibility given the attacker model, exposure, and whether an exploit exists.
  • Impact is data loss, downtime, financial, reputational and regulatory harm.

Writing the impact statement

Severity is a label; the impact statement is where risk becomes legible. Be specific about who, how feasibly, and what they get:

Weak: "This could be exploited by an attacker." Strong: "An unauthenticated attacker on the internal network could use this to reach Domain Admin within hours, giving full control of every system and all customer data."

Status, for completeness

Findings also carry a status that the report reflects honestly: open, then confirmed, then resolved, accepted (client owns the risk), withdrawn or duplicate. For recurring engagements, retest verdicts add verified_fixed, still_open, regressed and risk_accepted.

Related reading

  • Frameworks and standards
  • Glossary
Module anatomy

Knowledge check

Answer without AI. This is your own recall. 70% to pass.

  1. 1.A finding scores CVSS 9.8 but sits on an isolated, dataless, decommissioned box. How should you rate its risk?

  2. 2.Which CVSS metric group captures how important this specific asset is to the client?

  3. 3.What does the chain rule tell you to rate a finding for?

PreviousThe tool indexNextFAQ

On this page

  • The five severity levels
  • Using CVSS (v4.0) well
  • Likelihood times impact (for the matrix)
  • Writing the impact statement
  • Status, for completeness
  • Related reading
AI tutorComing soon

Ask questions and get hints as you work through this module, without leaving the page.

Ready when you are

Certify the dual mandate.

Start free, learn on subscription, and earn a verifiable credential recognised across the Five Eyes.

Start learningCompare certifications
STRIKEOPS ACADEMYPROFESSIONALSOCPCERTIFIED
StrikeOps Academy

The certification for operators who wield AI in offensive engagements and attack the AI systems inside every target.

Recognised across
AUCANZUKUS
Learn
  • Curriculum
  • Learning pathways
  • Search
Certify
  • Certifications
  • Pricing
  • Certification exams
Credentials
  • Associate · Silver
  • Professional · Gold
  • Expert · Platinum

Questions, or planning a team rollout?

Talk to our team and we will point you to the right track or credential.

Contact us

© 2026 StrikeOps Academy. A StrikeOps company. All rights reserved.

Privacy PolicyTerms of Service

The offensive techniques taught here are for authorised security testing only. The StrikeOps Academy labs are the sole sanctioned target unless you hold explicit written authorisation.