From the course: Vulnerability Management: Assessing the Risks with CVSS v3.1

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

How attack complexity affects risk

How attack complexity affects risk

From the course: Vulnerability Management: Assessing the Risks with CVSS v3.1

Start my 1-month free trial

How attack complexity affects risk

- [Instructor] Attack complexity is a simple metric compared to many of the others in the CVSS base group. Attack complexity is represented as AC in the CVSS vector string. Attack complexity only has two possible values, low and high. The value of low, represented by L in the vector string, means that no special situations are needed for an attack to be successful. The attacker can be reasonably certain of success when attacking a vulnerable system component. Since the likelihood of success is higher, the risk is too. The value of high, represented as H in the vector string, is selected in situations where a successful attack requires measurable effort on the attacker's part. Some examples of that sort of situation are needing to bypass or overcome mitigation techniques, like antivirus or anti-malware software, needing to understand specific details about the target system, or the environment, or its configurations, or…

Contents