{ "namespace": "vulnerability", "expanded": "vulnerability", "description": "A taxonomy for describing vulnerabilities (software, hardware, or social) on different scales or with additional available information.", "version": 7, "predicates": [ { "value": "sighting", "expanded": "Sighting", "description": "Sighting information related to the vulnerability.", "uuid": "823f943c-5490-54b2-8566-8ae26d2a460d" }, { "value": "exploitability", "expanded": "Exploitability", "description": "Quantification of attack exploitability, providing a level of exploitation for the identified vulnerability.", "exclusive": true, "uuid": "cc4b9f2a-8595-5d5b-9dd8-1e23534729a4" }, { "value": "information", "expanded": "Information", "description": "Complementary information related to the vulnerability.", "uuid": "60f8212b-460d-54d3-8a85-f4136f4a3071" }, { "value": "origin", "expanded": "Origin", "description": "Origin of the vulnerability.", "uuid": "bbfcf791-dad7-5ead-8f0c-21ec91549a56" }, { "value": "nvd", "expanded": "NVD", "description": "Tags used by the CVE program and documented at https://nvd.nist.gov/vuln/vulnerability-detail-pages.", "uuid": "711d6764-c246-417f-9996-245f3466653c" } ], "values": [ { "predicate": "sighting", "entry": [ { "value": "seen", "expanded": "Seen", "description": "The vulnerability was mentioned, discussed, or seen somewhere by the user.", "uuid": "47a1a26f-c1ae-500d-94a8-895f43e0fa50" }, { "value": "confirmed", "expanded": "Confirmed", "description": "The vulnerability is confirmed from an analyst perspective.", "uuid": "2c6df25f-7565-59a3-8675-291ea48563ea" }, { "value": "published-proof-of-concept", "expanded": "Published proof-of-concept", "description": "The vulnerability has a published public proof-of-concept.", "uuid": "7e5a611b-50b5-4283-9c98-1fdc98b1171c" }, { "value": "exploited", "expanded": "Exploited", "description": "This vulnerability was exploited and seen by the user reporting the sighting.", "uuid": "38941226-cfae-554f-8054-1330ba9191dd" }, { "value": "patched", "expanded": "Patched", "description": "This vulnerability was successfully patched by the user reporting the sighting.", "uuid": "bb9b16a0-7553-5132-8b40-5c029c07e3a0" }, { "value": "not-exploited", "expanded": "Not exploited", "description": "This vulnerability was not exploited or seen by the user reporting the sighting.", "uuid": "6a4bd64f-dfe6-5303-b52a-f6b6c8162930" }, { "value": "not-confirmed", "expanded": "Not confirmed", "description": "The user expresses doubt about the veracity of the vulnerability.", "uuid": "dabc0d44-21f2-5736-a3e2-7f594d4e6700" }, { "value": "not-patched", "expanded": "Not patched", "description": "This vulnerability was not successfully patched by the user reporting the sighting.", "uuid": "892a692b-4e55-56a8-abd0-de3101c33575" } ] }, { "predicate": "exploitability", "entry": [ { "value": "industrialised", "expanded": "Industrialised", "description": "Existing vulnerability with detailed attack methods; multiple tools are available for exploitation.", "uuid": "96a01875-60e7-5d43-93a2-7f26a3899c0e" }, { "value": "customised", "expanded": "Customised", "description": "Existing vulnerability with a detailed attack approach and one known custom tool available for exploitation.", "uuid": "4daf4561-df60-5eb3-a2af-df9bf7541342" }, { "value": "documented", "expanded": "Documented", "description": "Existing vulnerability is documented with an attack approach, but tools for exploitation are not available.", "uuid": "d11e21e5-7dd7-5c4f-aa9a-56b02d37301e" }, { "value": "theoretical", "expanded": "Theoretical", "description": "Publication describes a theoretical but no actual vulnerability is reported.", "uuid": "6f231ccd-d061-5fdd-98b5-95bd744a2d62" } ] }, { "predicate": "information", "entry": [ { "value": "PoC", "expanded": "Proof-of-Concept", "description": "Reference to a proof-of-concept for exploiting the vulnerability.", "uuid": "aae205e0-53b1-55a1-a12f-306ca47c05d5" }, { "value": "remediation", "expanded": "Remediation", "description": "Remediation to limit or block the exploitability of the vulnerability.", "uuid": "4375bb50-62b1-5afb-b04e-8c708b44da66" }, { "value": "annotation", "expanded": "Annotation", "description": "Annotation or clarification to a vulnerability.", "uuid": "82cc084c-2b38-55fc-b16c-473051147e87" }, { "value": "detection", "expanded": "Detection", "description": "Detection of a vulnerability or a vulnerable product.", "uuid": "243055fe-fb62-4124-b2b6-7e9c6ac417a7" } ] }, { "predicate": "origin", "entry": [ { "value": "hardware", "expanded": "Hardware", "description": "The origin of the vulnerability is hardware related.", "uuid": "0997619b-af1f-535d-b0fb-68c420a0e8dc" }, { "value": "software", "expanded": "Software", "description": "The origin of the vulnerability is software related.", "uuid": "26460cb4-6b27-5749-ba6a-6e1e84bc6b01" }, { "value": "service", "expanded": "Service", "description": "The origin of the vulnerability is service related.", "uuid": "ccc38fd3-1f41-5241-a3b1-8b0516481317" }, { "value": "procedural-implementation", "expanded": "Procedural implementation", "description": "The vulnerability originates from procedural implementation issues, such as misconfigurations or insecure configuration defaults introduced post-deployment, rather than being inherent to the original software or hardware distribution.", "uuid": "33f31021-2158-59ee-b6e4-f8499a9f0818" } ] }, { "predicate": "nvd", "entry": [ { "value": "disputed", "expanded": "Disputed", "description": "When one party disagrees with another party's assertion that a particular issue in software is a vulnerability, a CVE Record assigned to that issue may be tagged as being 'disputed'. ", "uuid": "4b0315fd-1d36-4216-8d93-b081dbdf4046" }, { "value": "unsupported-when-assigned", "expanded": "Unsupported When Assigned", "description": "Used by the assigning CNA to indicate that when a request for a CVE assignment was received, the product was already end-of-life (EOL) or a product or specific version was deemed not to be supported by the vendor. This tag should only be applied to a CVE Record when all affected products or version lines referenced in the CVE-Record are EOL.", "uuid": "0f9cb3bc-44f2-4eb7-921b-56e5a77ec322" }, { "value": "exclusively-hosted-service", "expanded": "Exclusively Hosted Service", "description": "All known software and/or hardware affected by this CVE Record is known to exist only in the affected hosted service. If the vulnerability affects both hosted and on-prem software and/or hardware, then the tag should not be used.", "uuid": "176e39c7-0e3b-4da3-b288-ec4f031b4db6" } ] } ], "uuid": "7639759c-8386-5aa9-b531-8a4081e65017" }