CVSS Scores or Risk Ratings in Pen Test Reports? Why You Need Both

Your penetration test report has arrived. It lists 47 findings, each with a CVSS score, and seven are marked “High.” Your developers say half of them do not matter in your environment, the testing firm says they all need fixing, and management wants to know what to do first. Meanwhile, another vendor’s sample report used “Critical, High, Medium, Low” business risk ratings with no CVSS at all. Which approach is actually more useful?

The short answer: CVSS scores are useful as a common language for technical severity, but they are not a measure of risk to your business. The most useful pen test reports include CVSS for consistency and comparison, then add a contextual risk rating that accounts for exploitability in your environment, what the vulnerability exposes, and whether it is being exploited in the wild. When buying a pen test, ask for both, with the reasoning behind any rating that differs from the CVSS score.

What CVSS measures, and what it does not

The Common Vulnerability Scoring System, maintained by FIRST, provides numerical scores indicating the severity of a vulnerability relative to others. The CVSS version 4.0 specification describes four groups of metrics: Base metrics for intrinsic characteristics, Threat metrics reflecting exploit availability and active exploitation, Environmental metrics for organisation-specific factors such as security controls and asset criticality, and optional Supplemental metrics.

Crucially, the specification positions CVSS as an input to vulnerability management processes that also consider factors outside CVSS, such as regulatory requirements, customer impact and financial consequences. A CVSS base score alone tells you how bad a flaw could be in general, not how much it matters to you.

Why a “High” may be low for you, and a “Medium” urgent

  • A high-scoring flaw on an internal test server with no sensitive data and no network path from the internet may be a low business risk.
  • A medium-scoring information disclosure on your customer portal that reveals account identifiers could enable a serious attack chain.
  • Several low findings combined, such as weak session handling plus verbose errors plus missing rate limits, may produce a critical path to account takeover.

Good testers explain those chains. Scores on individual findings cannot.

Other signals worth using alongside CVSS

Signal What it tells you
CVSS base score General technical severity; consistent across vendors
CVSS environmental and threat context Adjusted severity for your controls and current threat activity
EPSS FIRST’s model estimating the probability a published CVE will be exploited in the wild in the next 30 days
CISA Known Exploited Vulnerabilities catalog Whether a CVE is known to be actively exploited
Business context Data exposed, systems affected, regulatory impact, ease of detection

Note that EPSS and the KEV catalog apply to known CVEs in software you run. Many pen test findings, such as a custom application logic flaw, have no CVE, so tester judgment and business context carry more weight.

What a useful report looks like

  1. Executive summary in plain language: the most serious attack paths and what they would let an attacker do.
  2. Each finding with: description, affected assets, evidence, CVSS vector and score, a contextual risk rating, and a written justification when the two differ.
  3. Attack chains showing how findings combine.
  4. Clear, specific remediation steps, not generic advice.
  5. Retest results after fixes.

How to prioritise remediation

  • First: findings on internet-facing or sensitive systems that are easy to exploit, known to be exploited, or part of an attack chain to critical data.
  • Next: high severity findings on important internal systems.
  • Then: hardening items and low-risk findings, scheduled into normal work.

Agree remediation timelines by contextual risk rating, not raw CVSS, and document any accepted risks with an owner.

A hypothetical example: a SaaS company’s report has a CVSS 8.1 finding on a legacy admin interface already behind VPN and MFA, and a CVSS 5.3 flaw that lets users view other customers’ invoice numbers. The tester rates the second as higher business risk because it exposes customer data and enables enumeration. The company fixes it first.

If you are commissioning a test, see how to buy a penetration test and not an automated scan, and for testing your MSP’s detection, whether to pen test your MSP without telling them.

Pen test reports you can act on

A report is only valuable if it tells you what to fix first and why. AB7 Solutions’ cybersecurity team delivers vulnerability assessment and penetration testing (VAPT) reports with CVSS scoring for consistency, contextual business risk ratings with written justification, attack chain analysis, specific remediation guidance and retesting. If your existing report is sound and simply needs prioritising, we can help with that too.

Share a redacted copy of your latest report, and we will show you how we would prioritise its findings.

Email: ab@ab7solutions.com | director@ab7solutions.com
Phone: +91 9878067778 | +1 321 341 7733
Website: www.ab7solutions.com

Sources: FIRST, CVSS v4.0 Specification Document; FIRST, Exploit Prediction Scoring System (EPSS); CISA, Known Exploited Vulnerabilities Catalog.

Leave a Comment

Your email address will not be published. Required fields are marked *