Sure, some of it is open to interpretation, but I disagree with it not being taken seriously. This is the basis for CVEs, most bounty tables, and most audit reports (that I've seen).
CVSS scores are put into audit reports --- at the ouiji levels clients want --- to shut up the suits in compliance.
I'm not aware of any programs on HackerOne that don't follow this practice, so it's not "super uncommon".
I modified the assumptions that were made by the reporter and came out with Low.
This is one example of why this is a nonsense metric.