- Attack vector (AV:N)
- Could be attacked over the internet or any normal routed network.
- Attack complexity (AC:L)
- Exploitation conditions are straightforward and stable.
- Attack requirements (AT:N)
- No additional preconditions are required beyond normal reachability.
- Privileges required (PR:N)
- No privileges are required.
- User interaction (UI:P)
- A user has to participate (for example click/open/approve).
- Vulnerable system confidentiality impact (VC:N)
- No confidentiality impact on the vulnerable system.
- Vulnerable system integrity impact (VI:N)
- No integrity impact on the vulnerable system.
- Vulnerable system availability impact (VA:L)
- Limited availability impact on the vulnerable system.
- Subsequent system confidentiality impact (SC:N)
- No confidentiality impact on subsequent systems.
- Subsequent system integrity impact (SI:N)
- No integrity impact on subsequent systems.
- Subsequent system availability impact (SA:N)
- No availability impact on subsequent systems.
- Exploit maturity (threat) (E:P)
- Proof-of-concept: public PoC exists; no reported exploitation and no known simplification tools.