CVSSV4AttackRequirements captures the deployment and execution conditions of the vulnerable system that enable the attack in CVSS v4.0. NOT_DEFINED is valid only for modified (environmental) metric fields.
Values
| Enum Value | Description |
|---|---|
|
|
No special deployment or execution conditions are required for exploitation. |
|
|
Successful exploitation requires specific deployment or configuration prerequisites beyond the attacker's control. |
|
|
Assigning this value indicates insufficient information or the metric does not apply. Valid only for Modified Attack Requirements in environmental scoring. |
Used by
CVSSMetricV40type: Type CVSSMetricV40 contains detailed CVSS version 4.0 scoring attributes
Example
Example
"NONE"