on     off
background
 
Kris' Tech Blog
( and stuff )
Home
About Kris
Contact Kris
Categories
All by Date
Linux
Security
Networks
Religion
General
InfoSec Risk Severity Generator
InfoSec Risk Severity Generator
8-4-26
Kris Springer
Use this generator to estimate the risk severity of a cyber incident.
InfoSec Risk Severity
Click Here to edit this Title
—
0.0
/ 10.0
Score computed from the metrics below
Information Security
Attack Vector
?
How the attacker reaches the vulnerable component.
Network
— exploitable remotely over the internet or a network, no physical or local access needed.
Adjacent
— attacker must be on the same local network, subnet, or Bluetooth/adjacent link.
Local
— requires local access, such as a logged-in shell or terminal session.
Physical
— attacker needs to physically touch or interact with the device.
Network
Adjacent
Local
Physical
Attack Complexity
?
How much extra effort or luck the attacker needs beyond just reaching the target.
Low
— no special conditions; the exploit works reliably on demand.
High
— requires extra preparation, timing, or conditions outside the attacker's control (e.g. winning a race condition).
Low
High
Privileges Required
?
What level of access the attacker must already have before exploiting.
None
— no account or access needed at all.
Low
— needs a basic, low-privilege user account.
High
— needs administrative or elevated privileges already.
None
Low
High
User Interaction
?
Whether a person other than the attacker has to do something for the exploit to work.
None
— fully automated, no victim action needed.
Required
— a victim must take an action, like clicking a link or opening a file.
None
Required
Scope
?
Whether the impact stays contained to the vulnerable component or spreads beyond it.
Changed
— exploiting it can affect resources outside the vulnerable component's own security scope (e.g. escaping a sandbox).
Unchanged
— the impact is limited to the vulnerable component itself.
Changed
Unchanged
Confidentiality Impact
?
How much sensitive data the attacker could read or expose.
High
— total loss of confidentiality; attacker can read all data on the affected component.
Low
— some restricted data is exposed, but access or the amount is limited.
None
— no confidential data is disclosed.
High
Low
None
Integrity Impact
?
How much the attacker could modify or corrupt data or system behavior.
High
— attacker can modify any/all data, with a serious, direct consequence.
Low
— some data can be modified, but the attacker has limited control over what or how much.
None
— no loss of integrity; data can't be altered.
High
Low
None
Availability Impact
?
How much the attacker could degrade or deny access to the system or its data.
High
— total loss of availability; the resource is completely shut down or unreachable.
Low
— reduced performance or intermittent availability, but not a full outage.
None
— no impact to availability.
High
Low
None
Copy Image
Download PNG
© Copyright WarriorSon Productions. All rights reserved.