I think CVSS scores fundamentally failed by trying to apply one unified rubric to all systems and threat models.
consider the case where you're reviewing a SoC ASIC with a root of trust ROM, security processor, cryptographic accelerator, and main processor, with an internal AXI bus and external PCIe connection to a host, with each processor having internal security boundaries.
trying to maintain a coherent view of what "network", "adjacent network", and "local" mean is nearly impossible here.