Vulnerabilities · GraphQL enum

CVSSV4AttackVector enum

CVSSV4AttackVector describes the context from which a vulnerability can be exploited in CVSS v4.0. NOT_DEFINED is valid only for modified (environmental) metric fields.

Values

Enum Value Description

NETWORK

The attacker can exploit this vulnerability remotely across a network.

ADJACENT

Exploitation requires the attacker to be logically adjacent to the target (e.g., same LAN or Bluetooth). Note: CVSS v4.0 uses ADJACENT rather than ADJACENT_NETWORK.

LOCAL

Exploitation requires local access to the vulnerable system (e.g., via keyboard or shell).

PHYSICAL

Exploitation requires physical interaction with the vulnerable component.

NOT_DEFINED

Assigning this value indicates insufficient information or the metric does not apply. Valid only for Modified Attack Vector in environmental scoring.

Used by

  • CVSSMetricV40 type: Type CVSSMetricV40 contains detailed CVSS version 4.0 scoring attributes

Example

Example

"NETWORK"