Do you first need to determine whether a vulnerability applies?
CVSS ranks an applicable vulnerability; it does not prove applicability.
Yes. A scanner hit or corresponding version number does not prove that the vulnerable code is present, accessible or executable. Therefore, first check the component and version used, configuration, call route and any measures. Source code research, an SBOM, VEX, configuration analysis and dynamic testing can provide appropriate evidence for this.
If the product appears not to be affected, document this non-applicability with evidence. Don’t artificially give a low CVSS score to a vulnerability that doesn’t apply. FIRST also describes in the CVSS 4.0 FAQ that a supplier should reassess the score for the concrete product and can use VEX to communicate applicability.