Skip to main content

Attack Possibility

info

The English user guide is currently in beta preview. Most of the documents have been automatically translated from the Japanese version. Should you find any inaccuracies, please reach out to Flatt Security.

Alongside its severity, each vulnerability in a Takumi assessment report is assigned an attack possibility, which is classified into the following 4 levels.

PossibilityDescription
HighExploitable at any time, with no special precondition.
MediumExploitable once a certain condition is met, such as luring a victim into an action or an unusual configuration being in place.
LowRequires relatively complex conditions, or several conditions to hold at the same time.
ImpossibleCannot be carried out at the time of the assessment, or requires conditions an ordinary attacker cannot meet, such as already holding administrator privileges or the target's credentials.