The calculator estimates CVSS 3.1 base risk from exploitability and impact metrics.
Calculated Critical base severity using the selected CVSS 3.1 vector.
The score indicates technical severity, but final prioritization should also consider exposed users, exploit maturity, asset criticality and compensating controls.
Fix the root vulnerability, reduce exploitability, remove exposure, or add compensating controls. Update the CVSS vector after remediation to confirm risk reduction.
Retest the vulnerability and recalculate CVSS using the post-fix conditions.