Skip to content
  • There are no suggestions because the search field is empty.

How does Holm Security translate the CVSS score versions to severity?

How does Holm Security translate the CVSS score versions to severity?

This article describes how Holm Security translates a vulnerability's Common Vulnerability Scoring System (CVSS) score into a severity level. Severity levels are used throughout Security Center, for example to set max remediation times in compliance reports.

CVSS score to severity mapping

The table below shows how each CVSS score range translates into a Holm Security severity level. The same ranges apply regardless of which CVSS version is used to score a vulnerability: CVSS v2.0, CVSS v3.x, or CVSS v4.x.

Severity: Info: Low: Medium: High: Critical:
CVSS v2.0 score 0 0.1-3.9 4.0-6.9 7.0-8.9 9.0-10
CVSS v3.x score 0 0.1-3.9 4.0-6.9 7.0-8.9 9.0-10
CVSS v4.x score 0 0.1-3.9 4.0-6.9 7.0-8.9 9.0-10

What is an info severity?
Info is the lowest severity level (CVSS score of 0.0). It means no actual vulnerability was found, the finding is purely informational.