Previously, the CVSS score was displayed as an Overall Score, which could include Base, Temporal, and Environmental metrics.
Going forward, the CVSS score will reflect the Base Score published by the vendor.
Since Temporal and Environmental metrics vary over time and across organizational environments, they are not provided by the vendor. This meant that, in most cases, the Overall Score displayed was effectively the Base Score.
To avoid implying that these additional factors were included, we now display the Base Score directly as the CVSS score. In most cases, the score value will remain unchanged; only its representation is being made clearer.
For a more comprehensive view of vulnerability risk, our Risk Score considers real-world factors such as active exploitation, emerging threat intelligence, exploit availability, and exposure signals. This provides a more dynamic and actionable view of risk, helping you prioritize vulnerabilities that require immediate attention.
Cheers,
The ManageEngine Team