CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A vulnerability has fully functional exploit code publicly integrated into a widely used penetration testing framework, allowing virtually any attacker to reliably trigger it in most affected environments. When scoring the CVSS v3.1 Temporal metrics for this vulnerability, which value should be assigned to the Exploit Code Maturity (E) metric?
- AHigh (H)
- BFunctional (F)
- CProof-of-Concept (P)
- DUnproven (U)
Show answer & explanationAnswer & explanation
Correct answer: A. High (H)
CVSS v3.1 defines High (H) exploit code maturity as functional, autonomous code that works reliably in most situations, such as being integrated into a widely available automated tool like a popular exploitation framework. Functional (F) applies when working exploit code exists but is not fully reliable or automated everywhere.
Why the other options are wrong
- B. Functional exploit code works but is not the top tier of maturity/reliability.
- C. Proof-of-Concept means demonstration code exists but requires substantial modification.
- D. Unproven means no exploit code is available, contradicting the scenario.
CVSS Exploit Code Maturity (E)
A CVSS v3.1 Temporal metric describing the likelihood a vulnerability will be exploited, based on the availability and reliability of exploit code.
- Values: Not Defined, Unproven(U), Proof-of-Concept(P), Functional(F), High(H)
- High = autonomous, widely available exploit tool code
- Temporal metrics adjust score as exploit landscape changes over time
Memory trick: Exploit maturity grows: Unproven baby steps → PoC crawl → Functional walk → High sprint