7.0 hits my High rating (Medium tops off at 6.9) so it would need to be fully resolved within 30 days (Medium 60 days). I use the CVSS score as a starting point and then score to my organization so it may lower/raise the score based on a number of risk factors, including Intranet only.
CVSS is a great start, but it lacks context. Here's a few questions to start with evaluating the remediation timeline: 1. Who has access to this vulnerable System? 3rd Party/Contractors? Everyone in The Company? A few Employees? 2. Is accessing the System requires going through VPN or MFA? Is there an audit trail? 3. Are there any Security Controllers deployed before one gets an access this System? 4. Are there any Security Controllers deployed on the System, in case it gets comprised? 5. Is this System contains sensitive data? Can Data be leaked from it? Validating those points (and more), will help establish a more realistic, breach-oriented approach to the problem at hand.