1/11
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai |
|---|
No analytics yet
Send a link to your students to track their progress
Damage:
How bad would an attack be?
Reproducibility:
How easy is it to reproduce the attack?
Exploitability:
How much work is it to launch the attack?
Affected users:
How many people will be impacted?
Discoverability:
How easy is it to discover the threat?
Risk Rating
(Dai + Ri + Ei + Ai + Dii ) / 5
Impact =
(Damage + Affected Users)/2
Damage Scale
0: No damage
5: Information disclosure
8: Non-sensitive user data about individuals or employers have been compromisted
9: Non-sensitive administrative data was compromised
10: The destruction of an information system; the inaccessibility of data or applications
Reproducibility Scale
0: Difficult or impossible
5: Complex
10: Easy
Exploitability Scale
2.5: Advanced programming and networking skills
5: Available attack tools
10: Web browser
Affected Users Scale
0: No users
2.5: Individual user
6: Few users
8: Administrative users
10: All users
Discoverability Scale
0: Hard to discover the vulnerability
5: HTTP requests can uncover the vulnerability
10: Vulnerability found in the public domain