background 
Kris' Tech Blog ( and stuff ) Home About Kris Contact Kris

Categories


All by Date

Linux

Security

Networks

Religion

General





InfoSec Risk Severity Generator
InfoSec Risk Severity Generator 8-4-26
Kris Springer


Use this generator to estimate the risk severity of a cyber incident.

InfoSec Risk Severity
Click Here to edit this Title
0.0
/ 10.0
Information Security


Attack Vector
How the attacker reaches the vulnerable component.
Network
— exploitable remotely over the internet or a network, no physical or local access needed.
Adjacent
— attacker must be on the same local network, subnet, or Bluetooth/adjacent link.
Local
— requires local access, such as a logged-in shell or terminal session.
Physical
— attacker needs to physically touch or interact with the device.
Network
Adjacent
Local
Physical
Attack Complexity
How much extra effort or luck the attacker needs beyond just reaching the target.
Low
— no special conditions; the exploit works reliably on demand.
High
— requires extra preparation, timing, or conditions outside the attacker's control (e.g. winning a race condition).
Low
High
Privileges Required
What level of access the attacker must already have before exploiting.
None
— no account or access needed at all.
Low
— needs a basic, low-privilege user account.
High
— needs administrative or elevated privileges already.
None
Low
High
User Interaction
Whether a person other than the attacker has to do something for the exploit to work.
None
— fully automated, no victim action needed.
Required
— a victim must take an action, like clicking a link or opening a file.
None
Required
Scope
Whether the impact stays contained to the vulnerable component or spreads beyond it.
Changed
— exploiting it can affect resources outside the vulnerable component's own security scope (e.g. escaping a sandbox).
Unchanged
— the impact is limited to the vulnerable component itself.
Changed
Unchanged
Confidentiality Impact
How much sensitive data the attacker could read or expose.
High
— total loss of confidentiality; attacker can read all data on the affected component.
Low
— some restricted data is exposed, but access or the amount is limited.
None
— no confidential data is disclosed.
High
Low
None
Integrity Impact
How much the attacker could modify or corrupt data or system behavior.
High
— attacker can modify any/all data, with a serious, direct consequence.
Low
— some data can be modified, but the attacker has limited control over what or how much.
None
— no loss of integrity; data can't be altered.
High
Low
None
Availability Impact
How much the attacker could degrade or deny access to the system or its data.
High
— total loss of availability; the resource is completely shut down or unreachable.
Low
— reduced performance or intermittent availability, but not a full outage.
None
— no impact to availability.
High
Low
None







© Copyright WarriorSon Productions. All rights reserved.