Vulnerabilities · GraphQL enum

CVSSV4PrivilegesRequired enum

CVSSV4PrivilegesRequired describes the level of privileges an attacker must possess before exploiting the vulnerability in CVSS v4.0. NOT_DEFINED is valid only for modified (environmental) metric fields.

Values

Enum Value Description

NONE

The attacker is unauthorized and requires no prior access to files or settings.

LOW

The attacker requires user-level privileges that can typically be obtained with minimal effort.

HIGH

The attacker requires privileges providing significant control (e.g., administrative access).

NOT_DEFINED

Assigning this value indicates insufficient information or the metric does not apply. Valid only for Modified Privileges Required in environmental scoring.

Used by

  • CVSSMetricV40 type: Type CVSSMetricV40 contains detailed CVSS version 4.0 scoring attributes

Example

Example

"NONE"