Vulnerability BI — sidebar hides with the toggle

Exploitation Conditions

The prerequisites each record states in its own CVSS vector. This is published metadata about the vulnerability, not a statement about your network.

Mode: Global CVE catalogue
0 CVEs in scope
Global CVE catalogue
Supports investigation
Investigate if present — not detected exposure.

Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.

Data sources, exact rule, and what is unknown

Powered by: public.cves via fetchCves (CVSS v3 vector metrics only)

Rule: Stated-prerequisite score = 0.35 × AV + 0.25 × AC + 0.20 × PR + 0.20 × UI, read from the published CVSS vector. The funnel counts records whose vector states network vector, low complexity, no privileges and no user interaction.

Not known by this lens:
  • Observed reachability in your network: Not assessed
  • CVSS attack-vector metadata is not evidence that the service is reachable from anywhere in your environment.
  • Port observations alone never make an exploitation condition met.

Previously called “Attack Path Simplicity”. Renamed because the underlying evidence does not support that stronger claim.

All four conditions stated

0
AV:N, AC:L, PR:N, UI:N

Highest stated-prerequisite score

0

% stating network vector

0.0%

Records with no CVSS vector

0
Not assessed
How this works — definitions, thresholds, and what to doShow

Stated-prerequisite score = 0.35 × AV + 0.25 × AC + 0.20 × PR + 0.20 × UI, read from the published CVSS vector.

The funnel counts records whose vector states, in order: network attack vector, low attack complexity, no privileges required, no user interaction.

What this is not: observed reachability in your environment is Not assessed. A network attack vector in CVSS says nothing about whether the affected service is exposed on your estate, and an open port alone never makes an exploitation condition met.