Basic CVSS MITRE CVSS Rubric

An independent, guided questionnaire adapted from MITRE's "Rubric for Applying CVSS to Medical Devices" (© 2019 The MITRE Corporation, developed under contract to FDA). This implementation is not produced, reviewed, or endorsed by MITRE. It walks through medical-device-specific questions to arrive at the same CVSS score as Basic mode, and flags items with a Potential Impact to Patient Safety (PIPS).

Findings are kept only in your current browser session and are cleared when it ends — nothing is saved to a database or shared with anyone.

Guided questions from MITRE's "Rubric for Applying CVSS to Medical Devices" (Base Metric Group). Answers resolve to the same CVSS values as Basic mode.

0 of 8 metrics answered

Leave as-is to auto-assign the next ID, or type your own.
Prefills the description below. Metrics still come from the questions below, not NVD.
Attack Vector Not started
Attack Complexity Not started
Privileges Required Not started
User Interaction Not started
Scope Not started
Impact Metrics (Confidentiality / Integrity / Availability) 0 of 18

For each type of data or functionality below, answer whether the attacker could read it, modify/delete it, or prevent access to it. Use "None" for data types the device doesn't handle. Click a category's heading to collapse/expand it — answered categories collapse automatically.