CISA KEV · catalog date Dec 11, 2023 · first observed Jul 19, 2026
Evidence dossier
CVE-2023-6448
Unitronics VisiLogic uses a default administrative password
Exploited in the wild (CISA KEV since Dec 11, 2023). NVD reports CVSS 3.1 9.8. EPSS estimates 2.1% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.
- State
- PUBLISHED
- Published
- Dec 5, 2023
- Updated
- Oct 21, 2025
- Evidence coverage
- 98%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCAcisa-cgOriginal evidence ↗
Record text: Unitronics VisiLogic uses a default administrative password
Inspect raw assertion
- Field
container- Value
- Unitronics VisiLogic uses a default administrative password
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Unitronics Vision PLC and HMI Insecure Default Password Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Unitronics Vision PLC and HMI Insecure Default Password Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 2.07% probability · 80.05th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.020720000000; percentile 0.800470000000
FIRST EPSS · score date Aug 27, 2026 · 80th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
Unitronics VisiLogic uses a default administrative password
Inspect raw assertion
- Field
container- Value
- Unitronics VisiLogic uses a default administrative password
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Unitronics Vision PLC and HMI Insecure Default Password Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Unitronics Vision PLC and HMI Insecure Default Password Vulnerability
2.07% probability · 80.05th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.020720000000; percentile 0.800470000000
Applicability
Cited product scope
Grouped from 33 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
35 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "lessThan": "9.9.00", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "lessThan": "9.9.00", "versionType": "custom"}]product-ad1823feb7f591cf461b535a7e45bc73997352dc1fa42c729b0dc69aca9d003aLinked exactInspect raw assertion
cpe:2.3:h:unitronics:samba_3.5:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 14 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a510d42f-9299-4744-923e-1c828668431e
product-b97cb250142b5e4fd5d639b629ec8afb8998828309b78ec740eb1cf53ff91091Linked exactInspect raw assertion
cpe:2.3:o:unitronics:samba_3.5_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 14 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 12.38
- Match ID
0f976824-529b-4a9d-8c8b-a77f2c73819c
product-61b1a15e763f114cc6d19624708d5e8f73367be8e2e99ca8c7d78d62c209e202Linked exactInspect raw assertion
cpe:2.3:h:unitronics:samba_4.3:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 15 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ab661a2e-ded6-4bd7-9757-7592e786fd0e
product-4ab5aefa5cc7ed2c5a0347268f65c8ed1c41884500f1f521740014e4b2da128dLinked exactInspect raw assertion
cpe:2.3:o:unitronics:samba_4.3_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 15 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 12.38
- Match ID
7f3a2432-151d-4f10-a2a6-a39dcb3d43ee
product-156e56a28492461a7123d3562a1c7e6f1af7c53af384444bb86047c64c0ceb2bLinked exactInspect raw assertion
cpe:2.3:h:unitronics:samba_7:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 16 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
66362caa-4499-465d-86b2-1823de372137
product-6bdb6f9b572299e999f10cb4fa6b3e6ea4f78a9d620d149122fdc7773c6b411cLinked exactInspect raw assertion
cpe:2.3:o:unitronics:samba_7_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 16 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 12.38
- Match ID
41b9a502-15b8-45db-b169-b0317ec50ebf
product-fc599c2a850b92f258d7402904108864c616674c24612925e4ebc6fc62f5928cLinked exactInspect raw assertion
cpe:2.3:a:unitronics:visilogic:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 9.9.00
- Match ID
168d1c28-7a90-4d17-a3ee-1ea5f8c7aa0d
product-cc911b311bdc44ff8bb04a47e4b8c001c7323e2b97fb1da9bd65b53034c0559dLinked exactInspect raw assertion
cpe:2.3:h:unitronics:vision1040:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c91f4803-bc61-491f-9561-ecf043253b04
product-5c06f75d14101c0d967941c0a112f6a72d33adccdd749471ac5ee8250c49f0a9Linked exactInspect raw assertion
cpe:2.3:o:unitronics:vision1040_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 12.38
- Match ID
a7c3337b-e349-4303-b387-088978cc823c
product-128d5f1562e3777b84230a5b388d52d34393f7837e3b5bcdd6cc7f25a5c134bdLinked exactInspect raw assertion
cpe:2.3:h:unitronics:vision120:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 12 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cf245a2d-9c93-41c2-ad88-8b2aba026d5b
product-f2a5fad61a9c1e85541bcb482a2ad6c492879f079ded71728eb1dcf5d38153a2Linked exactInspect raw assertion
cpe:2.3:o:unitronics:vision120_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 12 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 12.38
- Match ID
ff329eb4-7af2-48e5-ad8a-ec5c3e3c22eb
product-e93588f404b50df7c23d404811e98b66510fb22e03de3ceea604140a0a29cadbLinked exactInspect raw assertion
cpe:2.3:h:unitronics:vision1210:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
32d6efd3-61c3-4c4d-8b17-16591255eae5
product-9ab1aee539a3039829792ab5abafa2a86d84370f7ae38bd551025ad8304b32c9Linked exactInspect raw assertion
cpe:2.3:o:unitronics:vision1210_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 12.38
- Match ID
cf1398a4-6bd7-48ff-8a65-7605da38ce23
product-7960d4cd1ad2d0fba4b6baa1080808b95f37114203b020c5f845c5bd5da48d79Linked exactInspect raw assertion
cpe:2.3:h:unitronics:vision130:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
49a6fc0d-8687-4563-9c38-5af0dcc46926
product-7658923fdb45dfead64b42e5453a905c369ba282bf03fa84470b312d729affb7Linked exactInspect raw assertion
cpe:2.3:o:unitronics:vision130_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 12.38
- Match ID
aa0b1985-f0c0-4554-98fb-b358f42b9f65
product-77bdf7e3ddf7b4b731421dcfc8bc176333c4dd5ee5597d93dafb31492bc5fc57Linked exactInspect raw assertion
cpe:2.3:h:unitronics:vision230:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 8 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c360b7f4-9fdb-4143-87a0-1006c7c3a39c
product-29ef52cff711938b7137eba0570c48b747198a93f10c872950242d7e30b561faLinked exactInspect raw assertion
cpe:2.3:o:unitronics:vision230_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 12.38
- Match ID
799f8466-30ac-4bd8-8ad5-35c2cfd98c37
product-d12a113336b750483c9bf77d4155046829f8858763acc5e2086c1faaebc0c5a7Linked exactInspect raw assertion
cpe:2.3:h:unitronics:vision280:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 9 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
519f0192-4f48-4954-bae1-8dc74bc0c017
product-b0e1cdcbf66ff479cd7975836034ec3c645900d554406a0d4afcb2b28da9b872Linked exactInspect raw assertion
cpe:2.3:o:unitronics:vision280_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 12.38
- Match ID
e7e91809-c43c-4acd-9f26-448ad25e9eef
product-b3df5e116c74d01fbd70a7fd46c3fa20c95714fe59b27157108bf2a1faba8314Linked exactInspect raw assertion
cpe:2.3:h:unitronics:vision290:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 10 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
66a05131-b264-4858-a533-cba5e229d40d
product-38aeb33e20231849ed8128ee6d98d510957b1a94aac89b77e5e6125ef2fac1b4Linked exactInspect raw assertion
cpe:2.3:o:unitronics:vision290_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 12.38
- Match ID
ecd944b5-2b08-4b9b-b0b0-17114fb58fb5
product-17ac370c900434f473c731a462ec8b541b8346adfdea160bfaed2df694074a02Linked exactInspect raw assertion
cpe:2.3:h:unitronics:vision350:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
406d6fa9-4c05-4612-811e-a32e4516ebc1
product-00f80b0f535f834df810c401981ae7935c3dbccbfc86fa3ce074a0338aaa957dLinked exactInspect raw assertion
cpe:2.3:o:unitronics:vision350_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 12.38
- Match ID
9e442c02-4684-4a3c-aa8f-ac641cca358c
Affected-product evidence
Accepted scope and product mapping
17 canonical links · 1 source-reported links
vendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-00f80b0f535f834df810c401981ae7935c3dbccbfc86fa3ce074a0338aaa957d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f0d281cc-fe42-4b4e-b41b-c09e976135c9vendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-29ef52cff711938b7137eba0570c48b747198a93f10c872950242d7e30b561fa
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5f18b259-1bd0-4ea2-a517-0c689887da56vendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-3266bf32f08b1278eef0e3df3b12d49a67162b35531e8e47cda615a83a6320b4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
08dfb072-e49c-4602-b753-81ec6bc58bfavendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-38aeb33e20231849ed8128ee6d98d510957b1a94aac89b77e5e6125ef2fac1b4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
366d3503-880a-4559-a297-db284f06ee86vendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-4ab5aefa5cc7ed2c5a0347268f65c8ed1c41884500f1f521740014e4b2da128d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
52e1d3aa-ee12-403c-ad82-6e8642985e46vendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-5c06f75d14101c0d967941c0a112f6a72d33adccdd749471ac5ee8250c49f0a9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c98e5907-2467-4533-94af-eab0685d6d35vendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-6bdb6f9b572299e999f10cb4fa6b3e6ea4f78a9d620d149122fdc7773c6b411c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5349cd18-2ff6-4fc8-8227-7bcf1de2c8a2vendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-7658923fdb45dfead64b42e5453a905c369ba282bf03fa84470b312d729affb7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2a8b444b-bcee-4abd-b61b-e2eeffd4d65fvendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-98b26a49d98717b725f00597d30319f684d075b672ed9f7c0d28816b623767ec
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3c73e7a1-a0aa-4127-aa88-5c8526de06b6vendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-9ab1aee539a3039829792ab5abafa2a86d84370f7ae38bd551025ad8304b32c9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6c3acb2a-a5a5-489c-a7b7-8985ca36062evendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-b036785ef4c3306f4515b546e6a13d5a017442675a8c2d40f52cdec5d320b35d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
77f74868-bee7-4b17-ac51-8d5bfa30139bvendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-b0e1cdcbf66ff479cd7975836034ec3c645900d554406a0d4afcb2b28da9b872
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8a2a0750-5495-4343-9bd7-602206c4d94dvendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-b2e89102761770c3415142c539ce935767e4a7209a5335fcc17e67b72bd78238
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4d531325-6d2f-499e-80b2-f08ce79c3351vendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-b97cb250142b5e4fd5d639b629ec8afb8998828309b78ec740eb1cf53ff91091
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0f5f5a4f-b1f3-4063-b083-9e01e33e234fvendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-c68e34a9e0bdb1f94d6b7a3f1da3c718e1d8ddd67dd1abefc578223d0a69c8e3
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2972d5a6-ce46-4ca8-9755-2dcfb00a10a4vendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-f2a5fad61a9c1e85541bcb482a2ad6c492879f079ded71728eb1dcf5d38153a2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4110b7e3-e913-4a8d-a148-daa11e84bd0evendor-e13af992ac9f4c88eb8991fe4fa1c4bf60ad72d2071ed56df65eb9c7203c1e47 · product-fc599c2a850b92f258d7402904108864c616674c24612925e4ebc6fc62f5928c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0a1a02a5-d9f3-4baf-8ecf-61c594749727Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2aa4060f-7a9e-4b63-8323-2ae31fc409baf5702bec-f534-4d81-9485-3f923618f2e1Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
cisa-cg
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.