Is CVSS 4.0 a risk score?

CVSS measures technical severity, but not the entire organizational risk.

No. CVSS describes the technical severity of a vulnerability. An organizational risk also includes, for example, the chance of misuse, the value and function of the system, people affected, legal obligations, possible damage and existing control measures.

FIRST therefore calls CVSS an input for the risk analysis. Factors such as financial damage, reputational damage, the number of affected customers and legal requirements are covered by expressly outside CVSS. An organization weighs these factors in its own risk management.