The same bug can receive different CVSS scores depending on the assumptions made during scoring — such as attack complexity, scope, and environmental context. External researchers and vendors may weigh these factors differently, sometimes leading to a critical vs. high discrepancy for the same flaw.