Recast CVSS scores and CVSS severities

In some situations, you might decide that a specific vulnerability poses a different level of risk to your environment than what is reflected in the original CVSS score or CVSS severity. In Cortex XSIAM you can override the CVSS score or severity within the platform. Customizing CVSS scores and severities enables you to align your risk management approach with your unique context and priorities.

When a CVSS score or severity is recast, the change is applied platform-wide, updating both existing and new vulnerability findings. This ensures consistency in how vulnerabilities are assessed and managed across the organization. After the CVSS score or severity is updated, the system automatically updates all affected findings within about one hour.

You can view the original CVSS score and severity and new values on the vulnerability details page in Vulnerability Intelligence.

Score changes do not occur in real time. Updates are triggered only when a Findings update takes place.

## How to recast the CVSS score and CVSS severity of a vulnerability

1. Navigate to **Home > Modules > Vulnerability & Exposure Management > Vulnerability Intelligence**.
2. Use the filters to find the vulnerability in the **Vulnerability Intelligence** table.
3. Click in the row for the vulnerability to open the vulnerability details panel.
4. Click the Options icon in the upper right corner and select **Override Severity or CVSS**.
5. Enter the new severity and score, and then click **Save**.

### View vulnerabilities with overridden CVSS severities and scores

Perform these steps to display the complete list of vulnerabilities with overridden CVSS severities and CVSS scores.

1. Navigate to **Posture Management** → **Vulnerability Management** → **Vulnerability Intelligence**.
2. Click the **Show Overridden CVSS** button in the upper right corner.

 You could also use the filter **Severity Source** _Contains_ **Custom Override** to display the list of vulnerabilities with overrides.