CVSS Environmental metrics

The environmental metrics adjust the score for your deployment: what the affected asset does and what else protects it.

They exist because the same flaw genuinely is more serious in some places than others, and the framework says so explicitly. Skipping them is the most common misuse of CVSS, and it is a misuse the specification itself warns about. The score was never intended to be consumed raw.

Checked against the primary source.

More on Vulnerability management