CVSSV4CIAImpact describes the impact on confidentiality, integrity, or availability of a successfully exploited system in CVSS v4.0. NEGLIGIBLE and SAFETY are valid only for Modified Subsequent System impact fields (MSC/MSI/MSA). SAFETY additionally applies only to MSI and MSA. NOT_DEFINED is valid only for modified (environmental) metric fields.
Values
| Enum Value | Description |
|---|---|
|
|
There is total loss of this property; the attacker has full control or causes complete unavailability. |
|
|
There is partial loss of this property, but the attacker does not have complete control. |
|
|
Impact to this property is negligible. Valid only for Modified Subsequent System impact fields (MSC, MSI, MSA). |
|
|
There is no impact to this property. |
|
|
Assigning this value indicates insufficient information or the metric does not apply. Valid only for Modified CIA Impact fields in environmental scoring. |
|
|
Exploitation of this vulnerability will affect the physical safety of humans. Valid only for Modified Subsequent System Integrity (MSI) and Availability (MSA) fields. |
Used by
CVSSMetricV40type: Type CVSSMetricV40 contains detailed CVSS version 4.0 scoring attributes
Example
Example
"HIGH"