A researcher can describe it as critical in text But CVE scoring has a real methodology with various frameworks and takes time to do properly, just have a look at the NIST CVSS calculator A valid critical 9+ cve score is more science than propaganda can it be that some of the redteam's critical vulnerabilities found are actually 7 or 8 cve? yes possible, but those are sill valid vulns to patch

Replies (3)

It does not take time to do CVSS scoring, and the CVSS scoring system is known to have issues many issues anyway. 1. Scores are often much lower or higher than they should be. 2. It is possible to easily over- or understate the impact of a vulnerability, intentionally or not. 3. Whether the vulnerability is actively exploitable is another question. After NIST had slowed down enrichment of CVEs, and many other safeguards broke, anyone can now go and issue a CVE for a project without any verification.
1000% also NIST funding not being renewed did cause chaos in the ecosystem, I agree it is not perfect