The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →FIRST announced CVSS version 3.1 on July 12, 2019, as a clarifying update to version 3.0—not a wholesale redesign. It refined definitions and guidance, introduced an Extensions Framework, and updated how vectors identify the version. CVSS 3.1 did not add metrics or metric values, and its formulas did not undergo major changes. FIRST now lists CVSS 4.0 as well as archived CVSS 3.1 resources, so 3.1 is the subject of that 2019 announcement, not FIRST’s newest version today.
What CVSS 3.1 is
The Common Vulnerability Scoring System (CVSS) is an open framework for describing characteristics and scoring the severity of software, hardware, and firmware vulnerabilities. FIRST’s specification says membership in FIRST is not required to use or implement CVSS. The Base score ranges from 0 to 10. A CVSS vector string records the metric values used to calculate a score, making the scoring choices visible rather than presenting a number alone. FIRST’s CVSS v3.1 specification
Three metric groups
- Base: intrinsic vulnerability characteristics intended to remain constant over time and across user environments.
- Temporal: factors that can change over time.
- Environmental: factors specific to a user’s environment.
Temporal and Environmental scoring can modify the Base score to reflect changing conditions or an organization’s circumstances.
What changed from CVSS 3.0 to 3.1?
FIRST described version 3.1 as a simplification and improvement of version 3.0 intended to make the system easier to adopt. The changes focused on clarifying existing concepts and supporting extensions, rather than expanding the core scoring metrics. FIRST’s July 12, 2019 announcement
#1 Best Overall
| Area | What changed in 3.1 |
|---|---|
| Metric definitions and guidance | Clarifications and refinements to Attack Vector, Privileges Required, Scope, and Security Requirements. |
| Core metric set | No new metrics or metric values were introduced. |
| Scoring formulas | No major formula changes. |
| Extensions | A CVSS Extensions Framework was added to support additional metrics and metric groups while retaining the standard Base, Temporal, and Environmental groups. |
| Glossary | Definitions were expanded and refined. |
| Vector version label | Version 3.1 vectors begin with CVSS:3.1. |
The practical effect is clearer interpretation and a way to describe extensions, while the familiar core metric set remains in place. FIRST’s v3.1 User Guide explains that the update clarified and improved the existing standard without new metrics or metric values and without major formula changes. Read the CVSS v3.1 User Guide
Does a CVSS score equal risk?
No. CVSS communicates vulnerability severity; a Base score by itself is not a complete assessment of the risk to a particular organization. The same vulnerability can matter differently depending on the systems exposed, the business impact, and the organization’s conditions—context CVSS Base metrics are not intended to capture.
Rank #2
For a more context-aware assessment, an organization can use Temporal and Environmental metrics and consider its own circumstances. When publishing a CVSS result, FIRST’s specification advises providing both the score and its vector, and following the document’s guidelines and attribution conditions. The vector lets readers see which metric values underpin the score.
Is CVSS 3.1 still current?
FIRST’s current CVSS resource index lists version 4.0 resources and keeps version 3.1 materials in an archive. That makes 3.1 relevant when reading or publishing work tied to that version, but it should not be described as FIRST’s newest CVSS version. Check the version associated with a score or vector rather than assuming scores from different versions are interchangeable. FIRST CVSS resources and version index
Rank #3
What FIRST said about CVSS’s purpose
In the announcement, FIRST attributed this statement to a CVSS SIG co-chair: “The primary goal of CVSS is to provide a deterministic and repeatable way to score the severity of vulnerabilities across many different constituencies.” The release excerpt does not identify the co-chair by personal name.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

