CVSSV4PrivilegesRequired describes the level of privileges an attacker must possess before exploiting the vulnerability in CVSS v4.0. NOT_DEFINED is valid only for modified (environmental) metric fields.
Values
| Enum Value | Description |
|---|---|
|
|
The attacker is unauthorized and requires no prior access to files or settings. |
|
|
The attacker requires user-level privileges that can typically be obtained with minimal effort. |
|
|
The attacker requires privileges providing significant control (e.g., administrative access). |
|
|
Assigning this value indicates insufficient information or the metric does not apply. Valid only for Modified Privileges Required in environmental scoring. |
Used by
CVSSMetricV40type: Type CVSSMetricV40 contains detailed CVSS version 4.0 scoring attributes
Example
Example
"NONE"