When including CVSS base scores in a final penetration test report, which combination of elements BEST prevents stakeholder misinterpretation of the organizational risk?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- AAn exploit-prediction probability and remediation timelines add urgency data, but without the vector string or local context readers still cannot see why the score fits their environment.
- BReporting an already modified number with a few sub-metrics hides how the score was built, so stakeholders cannot trace or challenge the adjustment that produced it.
- CGeneric scanner plugin text restates the finding but never explains how this flaw's severity changes on this particular asset, so the base number is still easy to misread.
- DCorrect: the vector string shows which metrics produced the number in CVSS v3.1 or v4.0, and a short environmental note ties that abstract score to this organization's real exposure.