You joke but I had to deal with an actual "high score CVE" internally that dealt with a denial-of-service vulnerability that happens when an administrator misconfigures the software. It literally boils down to "if you misconfigure the daemon it won't start == OMG HIGH RATING VULN".
I hate security theater. :(
One solution is there must be a higher bar of peer review to prevent issuance of bogus CVEs. Another approach would be to separate proposed vulns from confirmed/undisclosed ones. Human with good judgement in the loop is necessary to prevent DoS and spam.
In this case not only was the CVE a bullshit CVE, it also didn't properly scope the "affected" versions. The end result was that the version of the software we were running didn't even have the option that could potentially be misconfigured to cause the denial-of-service.
Enough security theatre, it's time for security opera
I remember having a public Hacker One program at one of the companies I worked at... Every day there were reports like that.
But it's only confirmed to be an outage when the status page says so. Until then, it is only degraded performance