The trait mix of the records in scope: what share state a network vector, no privileges, no interaction, or high impact.
Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.
Powered by: public.canonical_findings (canonical vendor, product, version, evidence quality) in environment mode · public.cves via fetchCves in catalogue mode
Rule: Each radar axis is a plain share of the records in scope: % network attack vector, % no privileges required, % no user interaction, % high confidentiality, % high integrity, % high availability, and mean CIA impact.
Each radar axis is a plain share of the records in scope, expressed as a percentage. Nothing is weighted or combined:
What this does not claim: a product with repeated CVEs is not thereby shown to have an architectural weakness — the shares describe published metadata only. Product presence on your assets is not assessed in catalogue mode.