CVSSV3AttackVector describes the context from which a vulnerability can be exploited in CVSS v3.x. NOT_DEFINED is valid only for modified (environmental) metric fields.
Values
| Enum Value | Description |
|---|---|
|
|
The attacker can exploit this vulnerability remotely across a network. |
|
|
Exploitation requires the attacker to be logically adjacent to the target (e.g., same LAN or Bluetooth). |
|
|
Exploitation requires local access to the vulnerable system (e.g., via keyboard or shell). |
|
|
Exploitation requires physical interaction with the vulnerable component (e.g., hardware attacks). |
|
|
Assigning this value indicates insufficient information or the metric does not apply. Valid only for Modified Attack Vector in environmental scoring. |
Used by
CVSSMetricV30type: Type CVSSMetricV30 contains detailed CVSS version 3.0 scoring attributesCVSSMetricV31type: Type CVSSMetricV31 contains detailed CVSS version 3.1 scoring attributes
Example
Example
"NETWORK"