vulnerability
Term · Cybersecurity · MLC-T-CYB-004586
1. Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
2. A known weakness in a system, system security procedures, internal controls, or implementation by which an actor or event may intentionally exploit or accidentally trigger the weakness to access, modify, or disrupt normal operations of a system-resulting in a security incident or a violation of the system's security policy.
3. Characteristic of design, location, security posture, operation, or any combination thereof, that renders an asset, system, network, or entity susceptible to disruption, destruction, or exploitation.
4. Weakness in a system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat.
5. Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source. Note: The term weakness is synonymous for deficiency. Weakness may result in security and/or privacy risks.
6. Weakness in an information system, or in system security procedures, internal controls, or implementation, that could be exploited or triggered by a threat source.
7. A flaw or weakness in a computer system, its security procedures, internal controls, or design and implementation, which could be exploited to violate the system security policy.
8. A security exposure in an operating system or other system software or application software component. A variety of organizations maintain publicly accessible databases of vulnerabilities based on the version numbers of software. Each vulnerability can potentially compromise the system or network if exploited.
9. A weakness that can be exploited or triggered to produce an adverse effect.
10. The inability to withstand adversity.
11. A condition that enables a threat event to occur.
12. A weakness in a system, system security procedures, internal controls, or implementation by which an actor or event may intentionally exploit or accidentally trigger the weakness to access, modify, or disrupt the normal operations of a system, resulting in a security incident or violation of the system’s security policy.
13. A weakness in system security procedures, system design, implementation, internal controls, etc., that could be exploited to violate the system security policy.
14. a bug, flaw, weakness, or exposure of an application, system, device, or service that could lead to a failure of confidentiality, integrity, or availability
15. An error, flaw, or mistake in computer software that permits or causes an unintended behavior to occur. CVE is a common means of enumerating vulnerabilities.
16. A weakness in system security procedures, hardware, design, implementation, internal controls, technical controls, physical controls, or other controls that could be accidentally triggered or intentionally exploited and result in a violation of the system's security policy.
17. A weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
| Identifier | MLC-T-CYB-004586 |
|---|---|
| Field | Cybersecurity |
| References | FIPS 200; NIST SP 1800-15B from NIST SP 800-37 Rev. 2; NIST SP 1800-15C from NIST SP 800-37 Rev. 2; NIST SP 1800-25B from FIPS 200, CNSSI 4009-2022 (Adapted); NIST SP 1800-26B from FIPS 200, CNSSI 4009-2022 (Adapted); NIST SP 1800-27B from FIPS 200; NIST SP 800-124r2 from NIST SP 800-53 Rev. 5; NIST SP 800-128; NIST SP 800-137; NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NIST SP 800-53 Rev. 5; NIST SP 800-53 Rev. 5 from NIST SP 800-30 Rev. 1; NIST SP 800-53A Rev. 5 from NIST SP 800-30 Rev. 1; NIST SP 800-60 Vol. 1 Rev. 1; NIST SP 800-60 Vol. 2 Rev. 1; NISTIR 7621 Rev. 1; NISTIR 7622 from FIPS 200, NIST SP 800-115; CNSSI 4009-2022; NIST SP 1800-21B from NIST SP 800-30 Rev. 1; NIST SP 800-12 Rev. 1 from NIST SP 800-30 Rev. 1; NIST SP 800-30 Rev. 1; NIST SP 800-39; NIST SP 800-82r3 from FIPS 200; NISTIR 8011 Vol. 4 from CNSSI 4009-2022; CNSSI 4009-2022 from DHS Lexicon Terms and Definitions; NIST SP 1800-17b; NIST SP 800-128 from CNSSI 4009-2022 (Adapted); NIST SP 800-37 Rev. 2; NIST SP 800-115; NIST SP 800-28 Version 2; NIST SP 800-44 Version 2; NIST SP 800-45 Version 2; NIST SP 800-160v1r1; NIST SP 800-221; NISTIR 8286; NIST SP 800-61r3 from CNSSI 4009-2022; NISTIR 4734; NISTIR 7435; NISTIR 7511 Rev. 4; NISTIR 7316; NIST IR 8270; NIST IR 8323r1 from NIST SP 800-30 Rev. 1; NIST IR 8401 from NIST SP 800-30 Rev. 1 (adapted); NIST IR 8441 from NIST SP 800-30 Rev. 1; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-004586",
"term": "vulnerability",
"field": "Cybersecurity",
"definition": "1. Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.\n\n2. A known weakness in a system, system security procedures, internal controls, or implementation by which an actor or event may intentionally exploit or accidentally trigger the weakness to access, modify, or disrupt normal operations of a system-resulting in a security incident or a violation of the system's security policy.\n\n3. Characteristic of design, location, security posture, operation, or any combination thereof, that renders an asset, system, network, or entity susceptible to disruption, destruction, or exploitation.\n\n4. Weakness in a system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat.\n\n5. Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source. Note: The term weakness is synonymous for deficiency. Weakness may result in security and/or privacy risks.\n\n6. Weakness in an information system, or in system security procedures, internal controls, or implementation, that could be exploited or triggered by a threat source.\n\n7. A flaw or weakness in a computer system, its security procedures, internal controls, or design and implementation, which could be exploited to violate the system security policy.\n\n8. A security exposure in an operating system or other system software or application software component. A variety of organizations maintain publicly accessible databases of vulnerabilities based on the version numbers of software. Each vulnerability can potentially compromise the system or network if exploited.\n\n9. A weakness that can be exploited or triggered to produce an adverse effect.\n\n10. The inability to withstand adversity.\n\n11. A condition that enables a threat event to occur.\n\n12. A weakness in a system, system security procedures, internal controls, or implementation by which an actor or event may intentionally exploit or accidentally trigger the weakness to access, modify, or disrupt the normal operations of a system, resulting in a security incident or violation of the system’s security policy.\n\n13. A weakness in system security procedures, system design, implementation, internal controls, etc., that could be exploited to violate the system security policy.\n\n14. a bug, flaw, weakness, or exposure of an application, system, device, or service that could lead to a failure of confidentiality, integrity, or availability\n\n15. An error, flaw, or mistake in computer software that permits or causes an unintended behavior to occur. CVE is a common means of enumerating vulnerabilities.\n\n16. A weakness in system security procedures, hardware, design, implementation, internal controls, technical controls, physical controls, or other controls that could be accidentally triggered or intentionally exploited and result in a violation of the system's security policy.\n\n17. A weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.",
"references": [
"FIPS 200; NIST SP 1800-15B from NIST SP 800-37 Rev. 2; NIST SP 1800-15C from NIST SP 800-37 Rev. 2; NIST SP 1800-25B from FIPS 200, CNSSI 4009-2022 (Adapted); NIST SP 1800-26B from FIPS 200, CNSSI 4009-2022 (Adapted); NIST SP 1800-27B from FIPS 200; NIST SP 800-124r2 from NIST SP 800-53 Rev. 5; NIST SP 800-128; NIST SP 800-137; NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NIST SP 800-53 Rev. 5; NIST SP 800-53 Rev. 5 from NIST SP 800-30 Rev. 1; NIST SP 800-53A Rev. 5 from NIST SP 800-30 Rev. 1; NIST SP 800-60 Vol. 1 Rev. 1; NIST SP 800-60 Vol. 2 Rev. 1; NISTIR 7621 Rev. 1; NISTIR 7622 from FIPS 200, NIST SP 800-115",
"CNSSI 4009-2022; NIST SP 1800-21B from NIST SP 800-30 Rev. 1; NIST SP 800-12 Rev. 1 from NIST SP 800-30 Rev. 1; NIST SP 800-30 Rev. 1; NIST SP 800-39; NIST SP 800-82r3 from FIPS 200; NISTIR 8011 Vol. 4 from CNSSI 4009-2022",
"CNSSI 4009-2022 from DHS Lexicon Terms and Definitions",
"NIST SP 1800-17b",
"NIST SP 800-128 from CNSSI 4009-2022 (Adapted); NIST SP 800-37 Rev. 2",
"NIST SP 800-115",
"NIST SP 800-28 Version 2",
"NIST SP 800-44 Version 2; NIST SP 800-45 Version 2",
"NIST SP 800-160v1r1",
"NIST SP 800-221; NISTIR 8286",
"NIST SP 800-61r3 from CNSSI 4009-2022",
"NISTIR 4734",
"NISTIR 7435",
"NISTIR 7511 Rev. 4",
"NISTIR 7316",
"NIST IR 8270; NIST IR 8323r1 from NIST SP 800-30 Rev. 1; NIST IR 8401 from NIST SP 800-30 Rev. 1 (adapted); NIST IR 8441 from NIST SP 800-30 Rev. 1",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/vulnerability/"
}
Record 4,586 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.