The system used to classify the severity of a vulnerability.

Classifications

Source

Vulnerability impact. It could impact:

  • Software
  • Configurations

Exposure Factor

A measure of how much can be lost if an organization suffers from this attack.

Environmental Variables

Based off what environment is required for this vulnerability