> setting “fixed” (fake) scores on our CVE entries just in order to prevent CISA or anyone else to ruin them, but we have decided not to since that would be close to lying<p>No, I really think this is the way. Pick fixed CVSS scores for each of your own LOW/MED/HIGH levels. Anyone who pays attention will know what's up, anyone who doesn't pay attention wasn't seeing enough detail to be meaningfully misled either way.<p>Think about it like significant figures, where too much precision is actually more of a lie than including all possible detail.