CVSS 4.0 Calculator

Pick the eleven CVSS v4.0 Base metrics and get the base score, the severity band, the macrovector, and the full vector string. The scoring runs entirely in your browser and nothing is sent anywhere.

This computes the CVSS v4.0 Base score only, which FIRST calls CVSS-B. Threat metrics (Exploit Maturity) and Environmental metrics (CR, IR, AR and the Modified Base metrics) are held at their "Not Defined" defaults, exactly as a published base score does. The arithmetic is the official FIRST algorithm, meaning macrovector lookup plus interpolation over the lower macrovector distances. It is not an approximation, and it was verified against the FIRST reference implementation across all 104,976 base-metric combinations.
Attack Vector (AV)
The context from which exploitation is possible.
N = routable from the internet. A = same logical network segment. L = local access or a shell. P = physical contact with the device.
Attack Complexity (AC)
Evasion or circumvention of built-in security-hardening measures.
H means the attacker must defeat a mitigation such as ASLR or a canary. In v4.0 this is strictly about hardening, not about luck or timing.
Attack Requirements (AT)
Deployment or execution preconditions outside the attacker's control. New in v4.0.
P covers race conditions, a required man-in-the-middle position, or a non-default configuration. v3.1 used to lump all of that into Attack Complexity.
Privileges Required (PR)
Privileges the attacker must already hold before the attack.
N = unauthenticated. L = an ordinary user account. H = administrative or equivalent control.
User Interaction (UI)
Whether a human other than the attacker must act. v4.0 splits this into two levels.
P = the victim only has to do something routine, like view a page. A = the victim must take a deliberate, targeted action, like importing a crafted file.
Confidentiality, Vulnerable System (VC)
Loss of confidentiality in the system that contains the flaw.
H = total loss, or disclosure of information that is directly serious. L = limited or attacker-uncontrolled disclosure.
Integrity, Vulnerable System (VI)
Loss of integrity in the system that contains the flaw.
H = the attacker can modify any data, or the modification has a direct serious consequence.
Availability, Vulnerable System (VA)
Loss of availability in the system that contains the flaw.
H = the attacker can fully deny the service, or deny it persistently. L = reduced performance or interruptions.
Confidentiality, Subsequent System (SC)
Confidentiality impact on systems beyond the vulnerable one. Replaces the v3.1 Scope metric.
Use this when the flaw lets an attacker read data belonging to a different security authority, such as another tenant or the host from a guest.
Integrity, Subsequent System (SI)
Integrity impact on systems beyond the vulnerable one.
Server-side request forgery and container escapes are the usual reasons this is not None.
Availability, Subsequent System (SA)
Availability impact on systems beyond the vulnerable one.
Set this when exploiting the flaw takes down a downstream or neighbouring system, not just the vulnerable component.
CVSS v4.0 Base Score (CVSS-B)
0.0
NONE
MacroVector
000000
Equivalence classes EQ1 to EQ6
Vector String
CVSS:4.0/
EQValueDriven byMeaning for this vector
For comparison, CVSS 3.1:

FIRST publishes no official conversion between v3.1 and v4.0, and the two versions measure different things. The line above is an unofficial illustrative mapping computed with the real v3.1 equations: AV and PR map directly, AT:P folds into AC:H, UI:P and UI:A both become UI:R, VC/VI/VA become C/I/A, and any non-None subsequent-system impact becomes Scope:Changed. Treat it as a rough sanity check, never as a converted score. For real v3.1 work use the CVSS 3.1 calculator.

Why CVSS 4.0 has no scoring formula

CVSS v3.1 was a closed-form equation. You looked up a numeric weight for each metric, multiplied an exploitability term by an impact term, and rounded up. You could compute it on paper.

CVSS v4.0 abandoned that. The v3.1 equation produced a well-known clustering problem, where a large share of all real vulnerabilities landed between 7.0 and 9.8 and the score stopped discriminating. Instead of fitting a new equation, the v4.0 special interest group had a panel of experts rank a large set of representative vectors by hand, and the standard now encodes those human judgements directly.

The macrovector

There are far too many distinct v4.0 vectors to rank individually, so the specification collapses the metrics into six equivalence classes, EQ1 through EQ6. Each class becomes a single digit, and the six digits together form the macrovector.

Every macrovector has a published score, which is the score of the most severe vector inside it. There are 270 of them, and that table is the actual standard. Nothing is calculated from metric weights.

Interpolation, which is the part people skip

A macrovector score alone would be far too coarse, because thousands of vectors share one macrovector and would all score identically. So the specification interpolates downward from the macrovector's ceiling.

score = macrovector_score - mean( available_distance(EQn) × severity_distance(EQn) / depth(EQn) )

For each equivalence class the algorithm finds the next lower macrovector, takes the gap between the two published scores as the available room, measures how far the vector you selected sits from the most severe vector in its own macrovector, divides by the depth of that class, and multiplies. The mean of those proportional drops is subtracted from the ceiling and the result is rounded to one decimal place. EQ3 and EQ6 are handled as a single joint class because they are not independent, and when both are 0 there are two possible lower macrovectors, in which case the higher-scoring one is used.

This calculator implements that algorithm in full, including the joint EQ3 and EQ6 handling and the search for a valid highest-severity vector. It was checked against the FIRST reference implementation across all 104,976 possible base-metric combinations with zero mismatches, and against 413 real published CVE base vectors, also with zero mismatches.

What actually changed from 3.1

Using this in a bug bounty report

Paste the vector string, not just the number. A triager can re-derive your score from the vector and argue with a specific metric, which is a much shorter conversation than arguing about a single digit. The two metrics most often disputed are Attack Requirements and the subsequent-system impacts, so justify those explicitly in your writeup. Also remember that most programs still pay against their own severity table rather than against CVSS directly, and many have not moved to v4.0 yet, so include the v3.1 vector as well if the program asks for it.

The scoring tables and algorithm come from the FIRST CVSS v4.0 specification. The lookup and max-severity data are reproduced from the FIRST reference calculator, which is published under the BSD 2-Clause licence by FIRST, Red Hat and contributors.

Related Tools

CVSS 3.1 Calculator Password Entropy Calculator All Tools