How it works: Select values for each attack vector component (AV, AC, PR, UI, S, C, I, A). The calculator automatically computes the CVSS 3.1 base score and provides the vector string.
Attack Vector (AV)
How the vulnerability can be exploited
Network (N)
Adjacent (A)
Local (L)
Physical (P)
N=Remote, A=Local network, L=Local system, P=Physical access required
Attack Complexity (AC)
Conditions needed to exploit the vulnerability
Low (L)
High (H)
L=No special conditions, H=Specific conditions or race conditions required
Privileges Required (PR)
Authentication or privileges needed before exploit
None (N)
Low (L)
High (H)
N=No auth required, L=Low-privilege account, H=Administrator/root
User Interaction (UI)
User action required for successful exploitation
None (N)
Required (R)
N=No user action, R=User must click link, install software, etc.
Scope (S)
Impact outside the vulnerable component
Unchanged (U)
Changed (C)
U=Only the vulnerable component, C=Other components or systems affected
Confidentiality (C)
Impact on information disclosure
High (H)
Low (L)
None (N)
H=All data exposed, L=Some data exposed, N=No data loss
Integrity (I)
Impact on data modification
High (H)
Low (L)
None (N)
H=Complete data modification, L=Some data altered, N=No integrity impact
Availability (A)
Impact on service availability
High (H)
Low (L)
None (N)
H=Complete service outage, L=Partial availability loss, N=No availability impact