You joke but I had to deal with an actual "high score CVE" internally that dealt with a denial-of-service vulnerability that happens when an administrator misconfigures the software. It literally boils down to "if you misconfigure the daemon it won't start == OMG HIGH RATING VULN".
I hate security theater. :(