CompTIA CySA+ (CS0-003)Vulnerability ManagementHard

An analyst is scoring a newly discovered web application flaw using CVSS v3.1. The vulnerability can be exploited remotely over the network (AV:N), requires low attack complexity (AC:L), needs no privileges (PR:N), requires no user interaction (UI:N), does not change scope (S:U), and results in complete loss of confidentiality, integrity, and availability (C:H/I:H/A:H). What is the resulting CVSS v3.1 Base Score?

  1. A10.0 (Critical)
  2. B9.8 (Critical)
  3. C7.5 (High)
  4. D6.5 (Medium)
Show answer & explanation

Correct answer: B. 9.8 (Critical)

The vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H produces a CVSS v3.1 base score of 9.8, the well-known score for network-exploitable, unauthenticated, high-impact flaws (e.g., remote code execution worms). All metrics are at their most severe except scope, which is unchanged, keeping it just under the 10.0 maximum reserved for scope-changed criticals.

Why the other options are wrong

  • A. 10.0 requires Scope Changed (S:C), which is not present here.
  • C. 7.5 corresponds to a vector with high impact but reduced availability/integrity, not this full-impact case.
  • D. 6.5 does not match all maximum-severity metrics used here.

CVSS v3.1 Base Score

A 0-10 score computed from exploitability metrics (AV, AC, PR, UI, S) and impact metrics (C, I, A) to rate vulnerability severity.

  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H = 9.8
  • Scope Changed (S:C) can push score to 10.0
  • Severity ranges: 0.1-3.9 Low, 4.0-6.9 Medium, 7.0-8.9 High, 9.0-10.0 Critical

Memory trick: No privileges, no interaction, full impact = near-perfect danger score.

More Vulnerability Management questions