CVSSV3PrivilegesRequired describes the level of privileges an attacker must possess before successfully exploiting the vulnerability in CVSS v3.x. NOT_DEFINED is valid only for modified (environmental) metric fields.
Values
| Enum Value | Description |
|---|---|
|
|
The attacker is unauthorized and requires no access to settings or files. |
|
|
The attacker requires basic user capabilities that could normally be obtained with minimal effort. |
|
|
The attacker requires privileges providing significant control over the component (e.g., admin). |
|
|
Assigning this value indicates insufficient information or the metric does not apply. Valid only for Modified Privileges Required in environmental scoring. |
Used by
CVSSMetricV30type: Type CVSSMetricV30 contains detailed CVSS version 3.0 scoring attributesCVSSMetricV31type: Type CVSSMetricV31 contains detailed CVSS version 3.1 scoring attributes
Example
Example
"NONE"