AutoCVSS: Assessing the Performance of LLMs for Automated Software Vulnerability Scoring

3Citations
Citations of this article
9Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The growing volume of daily disclosed software vulnerabilities imposes significant pressure on security analysts, extending the time needed for analysis - an essential step for accurate risk prioritization. Meanwhile, the time between disclosure and exploitation is reducing, becoming shorter than the analysis time and increasing the window of opportunity for attackers. This study explores leveraging Large Language Models (LLMs) for automating vulnerability risk score prediction using the industrial CVSS standard. From our analysis across different data availability scenarios, LLMs can effectively complement supervised baselines in data-scarce settings. In the absence of any annotated data, such as during the transition to new versions of the standard, LLMs are the only viable approach, highlighting their value in improving vulnerability management.

Cite

CITATION STYLE

APA

Sanvito, D., Arriciati, G., Siracusano, G., Bifulco, R., & Carminati, M. (2025). AutoCVSS: Assessing the Performance of LLMs for Automated Software Vulnerability Scoring. In EMNLP 2025 - 2025 Conference on Empirical Methods in Natural Language Processing, Proceedings of the Industry Track (pp. 564–575). Association for Computational Linguistics (ACL). https://doi.org/10.18653/v1/2025.emnlp-industry.38

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free