CVSSV3Scope describes whether a successful attack can impact resources beyond the vulnerable component in CVSS v3.x. NOT_DEFINED is valid only for modified (environmental) metric fields.
Values
| Enum Value | Description |
|---|---|
|
|
Exploitation can only affect resources managed by the same authority as the vulnerable component. |
|
|
Exploitation can affect resources beyond the authorization scope of the vulnerable component. |
|
|
Assigning this value indicates insufficient information or the metric does not apply. Valid only for Modified Scope in environmental scoring. |
Used by
CVSSMetricV30type: Type CVSSMetricV30 contains detailed CVSS version 3.0 scoring attributesCVSSMetricV31type: Type CVSSMetricV31 contains detailed CVSS version 3.1 scoring attributes
Example
Example
"UNCHANGED"