Your CVSS 9.8 sits on a jump-host-only admin console and a 6.5 on the payments session path — which is worse?
answer
- refuse the comparison as posed
- rescore both before ordering the work
- reachability is not the same as asset value
- modified attack vector down, requirements up
- environmental can exceed the base score
basics
~20 sAlmost certainly the 6.5. Rescore both with environmental metrics: the admin console flaw needs an attacker already inside the private network, while the payments path has high confidentiality, integrity and availability requirements, which lifts its score.
solid answer
~50 sNeither number is a rating for your estate yet, so do not order the work from them. The 9.8 assumes an attacker who can reach the component over a network; in your deployment the console answers only inside a private VLAN entered through a jump host, so the honest environmental encoding is a modified attack vector of Adjacent, and the attacker position it implies is someone who already holds an internal foothold. That drops the number materially. The 6.5 sits in the session-issuing path of a card-payments switch, where confidentiality, integrity and availability requirements are all high — money, not just data — and raising those requirement metrics pushes the environmental score above the base. After rescoring, the two can invert. Present it as two rescored vectors with the assumption behind each stated, not as a gut call, and let the calculator do the arithmetic rather than guessing at the deltas.
go deeper
Learn that a Critical label is not automatically the first ticket. When two findings are compared, ask where each affected system sits and what it protects before ranking them.
Be able to name which environmental metric carries which correction: modified base metrics for reachability, privileges and impact, and the requirement metrics for how much the asset matters.
Expect to do this live on a whiteboard. Rescore both findings out loud, state the single assumption you replaced in each, and be explicit that you would verify the reachability claim before trusting the lower number.
Own the rule that environmental rescoring must run in both directions, and be ready to explain how you stop a rescoring practice from degenerating into a mechanism teams use only to argue their own findings down.
## The trap in the question Two findings, one Critical and one Medium, and an obvious answer that is usually wrong. The obvious answer is wrong because both numbers were produced by someone who had never seen your architecture. A senior candidate is expected to refuse the comparison as posed and rebuild it. ## Rescoring the 9.8 The admin console is an internal tool. It is not routed from the internet; a user reaches it only from inside a private VLAN, which itself is entered through a jump host. The base vector's network attack vector is not a lie about the software — the flaw genuinely is exploitable over a network — but it is a lie about your deployment. The environmental group exists for exactly this. Set the modified attack vector to Adjacent, which is the setting for a flaw limited to a shared logical or physical network rather than one routable from anywhere. That single change lowers the exploitability contribution and pulls the score down out of the top band. Be precise about what you have and have not claimed. You have not claimed the flaw is harmless. You have claimed that exploiting it requires the attacker to already be inside — an internal foothold, a compromised operator workstation, or a contractor with jump-host access. The asset at stake is administrative credentials, and an attacker who reaches it gains a great deal. So the rescored number stays serious; it just stops being the most urgent thing on the list purely by virtue of a published 9.8. Do not reach for the requirement metrics to express reachability. Confidentiality, integrity and availability requirements say how much the asset matters, not how hard it is to get at. Mixing those two up is the most common rescoring error, and an interviewer listening carefully will catch it. ## Rescoring the 6.5 The other finding is in the session-issuing path of a card-payments switch. Ask what a defect there costs. A forged or replayed session in that path is not a privacy incident, it is unauthorised movement of money, and the same path failing closed stops the switch settling transactions at all. So the confidentiality requirement is high, the integrity requirement is high, and the availability requirement is high — a rare case where all three genuinely are. Requirement metrics default to a neutral middle setting, which is why an unrescored finding is implicitly being treated as sitting on an average asset. Raising all three increases the weight of the matching impact terms, and the environmental score rises **above** the published base. This is the half of environmental scoring that teams forget exists: they reach for it to argue findings down, and never to argue one up. ## The comparison you actually present Bring two rescored vectors and one sentence of context each: | Finding | Published | Assumption replaced | Direction | |---|---|---|---| | Admin console remote code execution | 9.8 | Reachable from anywhere, corrected to reachable from inside the private VLAN only | Down | | Payments session issuance | 6.5 | Average asset, corrected to money with all three requirements high | Up | That table is the deliverable. It converts an argument about intuition into an argument about two named assumptions, each of which someone can dispute on its merits. If a reviewer disagrees that the console is really unreachable — say, because a VPN concentrator terminates onto the same VLAN — the disagreement is about a fact of the network, which is resolvable, rather than about who feels more strongly. ## Traps to avoid **Editing the base vector.** Never rewrite the published base metrics to reflect your network. The base score is a shared reference; if you change it, nobody downstream can reconcile your findings with anyone else's. Corrections belong in the environmental group, which produces a distinct score alongside the untouched original. **Rescoring only downward.** A programme that only ever uses environmental metrics to shrink numbers has turned a rating method into an excuse generator. The payments example is the counterweight, and quoting one of each is the fastest way to show you use the tool honestly. **Guessing the arithmetic.** The metric weights are not intuitive and the formula is not linear. State the direction of each change confidently, then compute. A candidate who confidently asserts an exact rescored number they invented has just demonstrated the failure mode the whole question is about. **Forgetting the timer.** The lowered console score is true only while the console really is unreachable from outside. That adjusted number is a claim about the network's current shape, and it needs re-checking whenever that shape changes.
- Why not simply edit the base vector to say Adjacent instead?Because the base vector is a shared reference that must mean the same thing to everyone reading it. Rewriting it makes your findings irreconcilable with any other source and hides the fact that an adjustment was made at all. The environmental group produces a separate score while leaving the published one intact, so a reviewer can always see both the inherited claim and your correction side by side.
- How do you know the console really is only reachable from inside?You verify it rather than assert it, because the whole rescored number rests on that fact. Check what the load balancer and firewall rules actually permit, whether any VPN or partner circuit terminates onto that VLAN, and whether the jump host is the only path in practice. If nobody can demonstrate it today, score the finding as published until someone can.
- A reviewer says raising all three requirement metrics to high is score inflation. How do you respond?By justifying each one separately against the asset. Integrity is high because a forged session moves money. Availability is high because a failed switch stops settlement. Confidentiality is high because the same path handles cardholder identifiers. If any of those three arguments does not hold, I lower that metric rather than defend the set as a package — the discipline is per-property, and a reflexive triple-high is a fair thing to challenge.
saying these in an interview costs you the question
- Fixes the 9.8 first because Critical outranks Medium
- Uses requirement metrics to express network reachability
- Edits the published base vector instead of scoring environmentally
- Assumes environmental scoring can only lower a score
- Asserts an exact rescored number without computing it