CVSSV4AttackComplexity describes conditions beyond the attacker's control that must exist in order to exploit the vulnerability in CVSS v4.0. NOT_DEFINED is valid only for modified (environmental) metric fields.
Values
| Enum Value | Description |
|---|---|
|
|
No specialized access conditions or circumstances exist; exploitation is repeatable. |
|
|
A successful attack depends on conditions outside the attacker's control. |
|
|
Assigning this value indicates insufficient information or the metric does not apply. Valid only for Modified Attack Complexity in environmental scoring. |
Used by
CVSSMetricV40type: Type CVSSMetricV40 contains detailed CVSS version 4.0 scoring attributes
Example
Example
"LOW"