Recently after checking out the Heartbleed vulnerability I was taking a look at its CVSS score (AV:N/AC:L/Au:N/C:P/I:N/A:N) and noticed the following (partial) addendum:
CVSS V2 scoring evaluates the impact of the vulnerability on the host where the vulnerability is located. When evaluating the impact of this vulnerability to your organization, take into account the nature of the data that is being protected and act according to your organization’s risk acceptance.
After taking a look at CVSS v3 specification document I was not able to find a piece of text that quite explained whether the scoring system evaluates the impact similarly to its predecessor. If so, does CVSS v3 still evaluate a vulnerability based on the impact it has on the host?
The reason I ask is because Heartbleed seems to be rated way lower than what it deserves to be rated (relevant) and was wondering whether this would re-occur in a future vulnerability using CVSS v3.