Get the official CVSS v4.0 score and vector, plus a High, Medium or Low exploitability rating for your AAMI SW96 security risk assessment.
Reviewed by
Christian Espinosa
Founder & CEO, Blue Goat Cyber
CVSS v4.0 rates how severe a vulnerability is on a 0 to 10 scale. For medical devices, the exploitability rating should come from the five exploitability metrics (Attack Vector, Attack Complexity, Attack Requirements, Privileges Required, User Interaction), not the full score, because the full score also includes technical impact. Exploitability takes the place of probability in your AAMI SW96 assessment; severity of harm stays in your ISO 14971 file.
Real-world threat and patient safety
The FDA's February 2026 premarket cybersecurity guidance expects a security risk assessment that looks at exploitability, separate from the safety risk analysis. CVSS is one common way to describe exploitability and severity. Blue Goat Cyber uses it as an input, not the final answer.
No. The FDA does not mandate a specific scoring system. It expects a documented, justified method for assessing exploitability. CVSS is widely used, and the FDA-qualified MITRE rubric for applying CVSS to medical devices is a helpful reference.
Either can be justified. v4.0 adds the Safety flag and splits impact between the vulnerable system and downstream systems, which fits connected devices better. State which version you used and stay consistent across the file.
No. CVSS describes the vulnerability. Patient risk combines exploitability with severity of harm in your risk file.
What you'll see after you submit
Common misconceptions
Myth: FIRST's calculator Exploitability field is the exploitability rating.
Reality: That field uses only three metrics (AV, PR, UI). A sound rating uses all five exploitability metrics.
Myth: CVSS is the patient risk rating.
Reality: CVSS rates the vulnerability. Severity of harm is assessed separately under ISO 14971.
Myth: A Low CVSS finding can always be accepted.
Reality: Acceptance depends on your predefined criteria and patient-harm impact, and KEV-listed vulnerabilities should be fixed.
References & further reading
How exploitability and severity of harm fit together.
Read ISO 14971 and AAMI SW96 guideMetric groups, vector strings and a worked example.
Read CVSS scoring for medical devicesFindings scored, traced, and retested until closed.
Read Medical device penetration testingCheck your existing threat model and hazard analysis.
Read Threat model gap assessmentFree FDA cybersecurity tools.
Read More tools