- Attack vector (AV:L)
- Attacker needs local access on the target system.
- Attack complexity (AC:H)
- Exploitation depends on constrained or hard-to-reproduce conditions.
- Attack requirements (AT:P)
- Additional preconditions must be present for exploitation.
- Privileges required (PR:L)
- Low privileges are required.
- User interaction (UI:P)
- A user has to participate (for example click/open/approve).
- Vulnerable system confidentiality impact (VC:H)
- High confidentiality impact on the vulnerable system.
- Vulnerable system integrity impact (VI:N)
- No integrity impact on the vulnerable system.
- Vulnerable system availability impact (VA:N)
- No availability impact on the vulnerable system.
- Subsequent system confidentiality impact (SC:H)
- High confidentiality impact on subsequent systems.
- Subsequent system integrity impact (SI:H)
- High integrity impact on subsequent systems.
- Subsequent system availability impact (SA:N)
- No availability impact on subsequent systems.
- Exploit maturity (threat) (E:U)
- Unreported: no public PoC, no reported exploitation, and no known simplification tools.
- Safety (supplemental) (S:N)
- Negligible: impact meets the IEC 61508 negligible safety consequence category.
- Automatable (supplemental) (AU:N)
- No: attackers cannot reliably automate reconnaissance through exploitation for this issue.
- Recovery (supplemental) (R:A)
- Automatic: services recover on their own after an attack.
- Value density (supplemental) (V:C)
- Concentrated: a single exploit event controls rich resources (e.g., a central server).
- Vulnerability response effort (supplemental) (RE:L)
- Low/trivial response effort (documentation, simple configuration, low-touch guidance).
- Provider urgency (supplemental) (U:GREEN)
- Green: provider rates reduced urgency.