- Attack vector (AV:L)
- Attacker needs local access on the target system.
- Attack complexity (AC:L)
- Exploitation conditions are straightforward and stable.
- Attack requirements (AT:N)
- No additional preconditions are required beyond normal reachability.
- Privileges required (PR:N)
- No privileges are required.
- User interaction (UI:A)
- User interaction is required in an active way.
- Vulnerable system confidentiality impact (VC:N)
- No confidentiality impact on the vulnerable system.
- Vulnerable system integrity impact (VI:H)
- High integrity impact on the vulnerable system.
- Vulnerable system availability impact (VA:N)
- No availability impact on the vulnerable system.
- Subsequent system confidentiality impact (SC:N)
- No confidentiality impact on subsequent systems.
- Subsequent system integrity impact (SI:N)
- No integrity impact on subsequent systems.
- Subsequent system availability impact (SA:N)
- No availability impact on subsequent systems.
- Exploit maturity (threat) (E:X)
- Not defined: no reliable threat intelligence; scoring assumes the worst case (equivalent to Attacked).
- Confidentiality requirement (CR:X)
- Not defined: insufficient information; scoring treats this like High (worst case).
- Integrity requirement (IR:X)
- Not defined: insufficient information; scoring treats this like High (worst case).
- Availability requirement (AR:X)
- Not defined: insufficient information; scoring treats this like High (worst case).
- Modified attack vector (MAV:X)
- Not defined: scoring uses the Base Attack Vector (AV).
- Modified attack complexity (MAC:X)
- Not defined: scoring uses the Base Attack Complexity (AC).
- Modified attack requirements (MAT:X)
- Not defined: scoring uses the Base Attack Requirements (AT).
- Modified privileges required (MPR:X)
- Not defined: scoring uses the Base Privileges Required (PR).
- Modified user interaction (MUI:X)
- Not defined: scoring uses the Base User Interaction (UI).
- Modified vulnerable system confidentiality impact (MVC:X)
- Not defined: scoring uses the Base VC metric.
- Modified vulnerable system integrity impact (MVI:X)
- Not defined: scoring uses the Base VI metric.
- Modified vulnerable system availability impact (MVA:X)
- Not defined: scoring uses the Base VA metric.
- Modified subsequent system confidentiality impact (MSC:X)
- Not defined: scoring uses the Base SC metric.
- Modified subsequent system integrity impact (MSI:X)
- Not defined: scoring uses the Base SI metric.
- Modified subsequent system availability impact (MSA:X)
- Not defined: scoring uses the Base SA metric.
- Safety (supplemental) (S:X)
- Not evaluated.
- Automatable (supplemental) (AU:N)
- No: attackers cannot reliably automate reconnaissance through exploitation for this issue.
- Recovery (supplemental) (R:U)
- User: manual user intervention is needed to recover services.
- Value density (supplemental) (V:C)
- Concentrated: a single exploit event controls rich resources (e.g., a central server).
- Vulnerability response effort (supplemental) (RE:L)
- Low/trivial response effort (documentation, simple configuration, low-touch guidance).
- Provider urgency (supplemental) (U:GREEN)
- Green: provider rates reduced urgency.