CompTIA CySA+ (CS0-003)Vulnerability ManagementHard

An analyst is scoring a vulnerability in a hypervisor management API using CVSS v3.1. An authenticated low-privileged user (PR:L) can send a crafted request over the network (AV:N, AC:L, UI:N) that escapes the guest VM and gains complete control of the underlying host, impacting resources far beyond the vulnerable API's own security authority. Which Scope value should be selected, and how does it change the resulting base score compared to leaving Scope unchanged?

  1. AScope: Unchanged, because authentication is required so the impact cannot cross a security boundary
  2. BScope: Changed, but this metric always lowers the score whenever Privileges Required is Low
  3. CScope: Changed, because impact extends beyond the vulnerable component's security authority, which raises the base score (e.g., from 8.8 to 9.9 for this metric combination)
  4. DScope: Unchanged, because Scope does not factor into the base score calculation
Show answer & explanation

Correct answer: C. Scope: Changed, because impact extends beyond the vulnerable component's security authority, which raises the base score (e.g., from 8.8 to 9.9 for this metric combination)

Scope (S) is Changed when a vulnerability in one security authority (the guest VM) affects resources governed by a different authority (the host). Setting S:C also alters the CVSS formula's Privileges Required weighting and impact calculation, increasing the base score for AV:N/AC:L/PR:L/UI:N/C:H/I:H/A:H from 8.8 (Scope Unchanged) to 9.9 (Scope Changed), reflecting the greater real-world danger of an authority-crossing exploit.

Why the other options are wrong

  • A. Authentication (PR) and Scope are independent metrics; requiring auth does not prevent a scope change.
  • B. Scope's effect on score direction depends on the full metric set, not a fixed rule tied only to PR.
  • D. Scope directly affects both the exploitability formula and final score; it is not ignored.

CVSS Scope (S)

A CVSS v3.1 base metric indicating whether a vulnerability in one security authority (e.g., a VM, sandbox, or application) can impact resources controlled by a different security authority; values are Unchanged (S:U) or Changed (S:C).

  • S:C applies to sandbox/VM escapes, container breakouts, and cross-privilege-domain impacts
  • Changing Scope alters the underlying CVSS formula, typically increasing the base score
  • Example: identical metrics with S:U vs S:C can shift a score from 8.8 to 9.9

Memory trick: Scope Changed = the fire jumps over the firewall into the neighbor's house.

More Vulnerability Management questions