Why is CVSS 4.0 in MIAUW?
CVSS captures technical severity and assumptions in a repeatable manner.
CVSS 4.0 provides an open, vendor-neutral method to capture the technical characteristics and severity of a vulnerability. The vector also shows which values and assumptions led to the score. This makes an assessment more transferable and verifiable than just the label ‘high’ or ‘critical’.
MIAUW uses this common measurement language to report the severity and substantiation of findings in an imitable manner. MIAUW does not automatically determine whether a vulnerability applies and does not prescribe a recovery decision. According to the official specification of FIRST, CVSS is an input to risk analysis, not the complete risk analysis.