CompTIA CySA+ (CS0-003)Vulnerability ManagementHard
An analyst is scoring a newly discovered web application flaw using CVSS v3.1. The vulnerability can be exploited remotely over the network (AV:N), requires low attack complexity (AC:L), needs no privileges (PR:N), requires no user interaction (UI:N), does not change scope (S:U), and results in complete loss of confidentiality, integrity, and availability (C:H/I:H/A:H). What is the resulting CVSS v3.1 Base Score?
- A10.0 (Critical)
- B9.8 (Critical)
- C7.5 (High)
- D6.5 (Medium)
Show answer & explanationAnswer & explanation
Correct answer: B. 9.8 (Critical)
The vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H produces a CVSS v3.1 base score of 9.8, the well-known score for network-exploitable, unauthenticated, high-impact flaws (e.g., remote code execution worms). All metrics are at their most severe except scope, which is unchanged, keeping it just under the 10.0 maximum reserved for scope-changed criticals.
Why the other options are wrong
- A. 10.0 requires Scope Changed (S:C), which is not present here.
- C. 7.5 corresponds to a vector with high impact but reduced availability/integrity, not this full-impact case.
- D. 6.5 does not match all maximum-severity metrics used here.
CVSS v3.1 Base Score
A 0-10 score computed from exploitability metrics (AV, AC, PR, UI, S) and impact metrics (C, I, A) to rate vulnerability severity.
- AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H = 9.8
- Scope Changed (S:C) can push score to 10.0
- Severity ranges: 0.1-3.9 Low, 4.0-6.9 Medium, 7.0-8.9 High, 9.0-10.0 Critical
Memory trick: No privileges, no interaction, full impact = near-perfect danger score.