Top Five Vulnerability Classification Scale
1 Low severity vulnerabilities
Include information disclosure or other type of vulnerability that doesn’t pose much of a risk by itself, but if used with other information, may be exploited.
2 Medium level vulnerabilities
Are ones that would require a very sophisticated attacker to pull it off, but it’s still possible.This could include a situation where a vulnerability is partially mitigated or there is a temporary fix in place.
3 High risk vulnerabilities
That could be serious if exploited, but there is no worm or prolific exploit. An example of this might be a vulnerability that could be exploited by a script kiddie level malicious user.
4 Critical vulnerabilities
That have not been used to exploit your system yet, but may be in the near future. An example of this could include a patch to your systems are missing and there is a known worm crawling the Internet exploiting this problem. While this is not as bad as a system that is currently compromised, it’s a close second and should be fixed soon.
5 Urgent vulnerabilities
That should be fixed as soon as possible. Basically this is when your system has been compromised and you should work to quickly get this fixed.







