The prerequisites each record states in its own CVSS vector. This is published metadata about the vulnerability, not a statement about your network.
Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.
Powered by: public.cves via fetchCves (CVSS v3 vector metrics only)
Rule: Stated-prerequisite score = 0.35 × AV + 0.25 × AC + 0.20 × PR + 0.20 × UI, read from the published CVSS vector. The funnel counts records whose vector states network vector, low complexity, no privileges and no user interaction.
Previously called “Attack Path Simplicity”. Renamed because the underlying evidence does not support that stronger claim.
Stated-prerequisite score = 0.35 × AV + 0.25 × AC + 0.20 × PR + 0.20 × UI, read from the published CVSS vector.
The funnel counts records whose vector states, in order: network attack vector, low attack complexity, no privileges required, no user interaction.
What this is not: observed reachability in your environment is Not assessed. A network attack vector in CVSS says nothing about whether the affected service is exposed on your estate, and an open port alone never makes an exploitation condition met.