Neatbo.

Why a 9.0 base score can accompany 9.1 environmental

The resolved original example follows the distinct CVSS 3.1 modified-impact formula and Roundup policy.

A reported discrepancy is not always a scoring defect

In issue #38, the author supplied CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H and saw 9.0 base versus 9.1 environmental without environmental entries. The maintainer explained that the FIRST reference and Decimal result match the specification, and closed the issue as a duplicate/not-a-bug. The resolved source supports a need to explain the result, rather than an instruction to make the scores equal.

The changed-scope formulas differ

With scope changed, base impact uses a power of 15 on ISS minus 0.02. CVSS 3.1 modified impact uses a power of 13 on MISS multiplied by 0.9731 minus 0.02. Requirements also affect MISS, which is capped at 0.915. Environmental scoring applies an inner Roundup before the temporal factors and an outer Roundup afterwards. Inheriting the same metric values therefore does not promise the same score.

Read the complete original result
Score groupOriginal resultDifferent calculation
Base9.0Original impact and exploitability
Temporal9.0Base score × E × RL × RC, then Roundup
Environmental9.1Modified impact/exploitability and nested Roundup

Roundup has a floating-point rule

FIRST Appendix A specifies integer-assisted rounding so tiny binary representation errors do not add an unwanted tenth. A plain floating-point ceil applied to a decimal-looking product can produce a different answer. T361 retains the complete FIRST 3.1 scoring core and reports its unrounded intermediate values beside the final one-decimal strings.

Check a scoring claim with its vector

Compare scores only after checking the exact version, source vector and supplied optional values. The full audit distinguishes omitted input from explicit X and shows which base value a modified metric inherited. Neither a severity band nor this historical issue proves exploitation in your own deployment.

  • Keep each score with its complete scoring vector.
  • Inspect modified scope before interpreting the MPR weight.
  • Keep the 9.0 / 9.0 / 9.1 original example intact when comparing calculators.
  • Use the linked operating guide to save every metric state, intermediate field and original byte.

References

Tools in this category

Expand a tool to see its steps, options and supported formats, then open its workspace.

CVSS 3.1 vector scoringScore complete local CVSS 3.1 vectors, inspect every metric and inheritance source, and retain all scores, intermediate values and original bytes.

Score complete local CVSS 3.1 vectors, inspect every metric and inheritance source, and retain all scores, intermediate values and original bytes.

Steps

  1. Choose one source and vector or CSV mode; supply complete records and stable IDs.
  2. Run locally, then inspect all three scores, scoring vectors, all 22 metric states and intermediate fields.
  3. Copy all scores and settings, or download the complete audit and unchanged original.

Capabilities and limits

  • Fixed CVSS 3.1: all eight base metrics required; up to 22 distinct metrics in any order. Explicit X and omitted optional metrics are retained separately.
  • One complete UTF-8 vector or CSV with exact id,vector header; unique nonempty IDs. Source order and duplicate vector values are preserved.
  • Simultaneous limits: 4 MiB input, 10,000 vectors, 512 ASCII bytes/vector, 128 UTF-8 bytes/ID, 2 million total work units; 64 MiB files plus text/copy, 8 MiB typed data, 72 MiB aggregate, 96 MiB wire, 256 MiB owned reservation and one absolute 30-second period. Limits are gates, not a claim that every isolated maximum can be reached together.
  • All inputs are local. No CVE lookup, vulnerability scan, metric inference or other CVSS version. Severity does not establish exploitability in a particular deployment.
  • Seven complete downloads: JSON audit, scores CSV, metric states CSV, intermediate formulas CSV, settings JSON, original bytes and full FIRST notice. Copy contains all scores and settings. Metric CSV joins to complete IDs through sourceRecord.
Open CVSS 3.1 vector scoring →