- Attack vector (AV:N)
- Could be attacked over the internet or any normal routed network.
- Attack complexity (AC:L)
- Exploitation conditions are straightforward and stable.
- Attack requirements (AT:N)
- No additional preconditions are required beyond normal reachability.
- Privileges required (PR:L)
- Low privileges are required.
- User interaction (UI:N)
- No user interaction is required.
- Vulnerable system confidentiality impact (VC:N)
- No confidentiality impact on the vulnerable system.
- Vulnerable system integrity impact (VI:N)
- No integrity impact on the vulnerable system.
- Vulnerable system availability impact (VA:L)
- Limited availability impact on the vulnerable system.
- Subsequent system confidentiality impact (SC:N)
- No confidentiality impact on subsequent systems.
- Subsequent system integrity impact (SI:N)
- No integrity impact on subsequent systems.
- Subsequent system availability impact (SA:N)
- No availability impact on subsequent systems.
- Exploit maturity (threat) (E:U)
- Unreported: no public PoC, no reported exploitation, and no known simplification tools.
- Confidentiality requirement (CR:X)
- Not defined: insufficient information; scoring treats this like High (worst case).
- Integrity requirement (IR:X)
- Not defined: insufficient information; scoring treats this like High (worst case).
- Availability requirement (AR:X)
- Not defined: insufficient information; scoring treats this like High (worst case).
- Modified attack vector (MAV:X)
- Not defined: scoring uses the Base Attack Vector (AV).
- Modified attack complexity (MAC:X)
- Not defined: scoring uses the Base Attack Complexity (AC).
- Modified attack requirements (MAT:X)
- Not defined: scoring uses the Base Attack Requirements (AT).
- Modified privileges required (MPR:X)
- Not defined: scoring uses the Base Privileges Required (PR).
- Modified user interaction (MUI:X)
- Not defined: scoring uses the Base User Interaction (UI).
- Modified vulnerable system confidentiality impact (MVC:X)
- Not defined: scoring uses the Base VC metric.
- Modified vulnerable system integrity impact (MVI:X)
- Not defined: scoring uses the Base VI metric.
- Modified vulnerable system availability impact (MVA:X)
- Not defined: scoring uses the Base VA metric.
- Modified subsequent system confidentiality impact (MSC:X)
- Not defined: scoring uses the Base SC metric.
- Modified subsequent system integrity impact (MSI:X)
- Not defined: scoring uses the Base SI metric.
- Modified subsequent system availability impact (MSA:X)
- Not defined: scoring uses the Base SA metric.
- Safety (supplemental) (S:N)
- Negligible: impact meets the IEC 61508 negligible safety consequence category.
- Automatable (supplemental) (AU:Y)
- Yes: all four kill-chain steps (reconnaissance, weaponization, delivery, exploitation) can be automated.
- Recovery (supplemental) (R:A)
- Automatic: services recover on their own after an attack.
- Value density (supplemental) (V:D)
- Diffuse: a single exploit event controls relatively limited resources (e.g., one client).
- Vulnerability response effort (supplemental) (RE:L)
- Low/trivial response effort (documentation, simple configuration, low-touch guidance).
- Provider urgency (supplemental) (U:CLEAR)
- Clear: provider rates this as informational urgency.