- Attack vector (AV:N)
- Could be attacked over the internet or any normal routed network.
- Attack complexity (AC:L)
- Exploitation conditions are straightforward and stable.
- Attack requirements (AT:N)
- No additional preconditions are required beyond normal reachability.
- Privileges required (PR:L)
- Low privileges are required.
- User interaction (UI:N)
- No user interaction is required.
- Vulnerable system confidentiality impact (VC:H)
- High confidentiality impact on the vulnerable system.
- Vulnerable system integrity impact (VI:H)
- High integrity impact on the vulnerable system.
- Vulnerable system availability impact (VA:H)
- High availability impact on the vulnerable system.
- Subsequent system confidentiality impact (SC:N)
- No confidentiality impact on subsequent systems.
- Subsequent system integrity impact (SI:N)
- No integrity impact on subsequent systems.
- Subsequent system availability impact (SA:N)
- No availability impact on subsequent systems.
- Exploit maturity (threat) (E:X)
- Not defined: no reliable threat intelligence; scoring assumes the worst case (equivalent to Attacked).
- Confidentiality requirement (CR:X)
- Not defined: insufficient information; scoring treats this like High (worst case).
- Integrity requirement (IR:X)
- Not defined: insufficient information; scoring treats this like High (worst case).
- Availability requirement (AR:X)
- Not defined: insufficient information; scoring treats this like High (worst case).
- Modified attack vector (MAV:X)
- Not defined: scoring uses the Base Attack Vector (AV).
- Modified attack complexity (MAC:X)
- Not defined: scoring uses the Base Attack Complexity (AC).
- Modified attack requirements (MAT:X)
- Not defined: scoring uses the Base Attack Requirements (AT).
- Modified privileges required (MPR:X)
- Not defined: scoring uses the Base Privileges Required (PR).
- Modified user interaction (MUI:X)
- Not defined: scoring uses the Base User Interaction (UI).
- Modified vulnerable system confidentiality impact (MVC:X)
- Not defined: scoring uses the Base VC metric.
- Modified vulnerable system integrity impact (MVI:X)
- Not defined: scoring uses the Base VI metric.
- Modified vulnerable system availability impact (MVA:X)
- Not defined: scoring uses the Base VA metric.
- Modified subsequent system confidentiality impact (MSC:X)
- Not defined: scoring uses the Base SC metric.
- Modified subsequent system integrity impact (MSI:X)
- Not defined: scoring uses the Base SI metric.
- Modified subsequent system availability impact (MSA:X)
- Not defined: scoring uses the Base SA metric.
- Safety (supplemental) (S:X)
- Not evaluated.
- Automatable (supplemental) (AU:X)
- Not evaluated.
- Recovery (supplemental) (R:X)
- Not evaluated.
- Value density (supplemental) (V:X)
- Not evaluated.
- Vulnerability response effort (supplemental) (RE:X)
- Not evaluated.
- Provider urgency (supplemental) (U:X)
- Not evaluated.