vulnerability
nounid
4629·updated May 9, 2026verified
Weakness in a component of a system, particularly information assets, system security procedures, internal controls, or implementation, that could be exploited or triggered by human action or natural events.
polysemous
Attested in
No recorded attestations. They are written when an MWE tagging stage is completed, stamped with the pack version and the document’s digest.
Classifications
Entity Type
Vulnerability95%rule-basedr:entity.vulnerability.cve.v1
Sensitivity
unclassified
Information Class
unclassified
Variants
- synonym
- exposure
- alternatephrasing
- Vulnerability
- plural
- vulnerabilities
- possessive
- vulnerability's
- pluralpossessive
- vulnerabilities'
Framework definitions
National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
- §1 · extended_definition_available
- A characteristic or specific weakness that renders an organization or asset (such as information or an information system) open to exploitation by a given threat or susceptible to a given hazard.
- §1
- A weakness in the design, implementation, operation or internal control of a process that could expose the system to adverse threats from threat events
- §1
- A weakness in an information system, administrative controls, internal controls, system security practices and procedures, implementation, or physical layout that could be accidentally triggered or intentionally exploited by a threat in order to gain unauthorized access to information or disrupt processing.
- §1
- A weakness in an information system, administrative controls, internal controls, system security practices and procedures, implementation, or physical layout that could be accidentally triggered or intentionally exploited by a threat in order to gain unauthorized access to information or disrupt processing.
- §1
- A weakness in an information system, administrative controls, internal controls, system security practices and procedures, implementation, or physical layout that could be accidentally triggered or intentionally exploited by a threat in order to gain unauthorized access to information or disrupt processing.
- §1
- A weakness in an information system, administrative controls, internal controls, system security practices and procedures, implementation, or physical layout that could be accidentally triggered or intentionally exploited by a threat in order to gain unauthorized access to information or disrupt processing.
- §1
- A weakness, susceptibility or flaw in a system that an attacker can access and exploit to compromise system security. Vulnerability arises from the confluence of three elements: the presence of a susceptibility or flaw in a system; an attacker’s access to that flaw; and an attacker’s capability to exploit the flaw.
Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
- §1
- A hardware, firmware, or software flaw that leaves an information system open to potential exploitation; a weakness in automated system security procedures, administrative controls, physical layout, internal controls, etc., that could be exploited to gain unauthorized access to information or to disrupt critical processing.
- §1
- Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
- §2 · sense_2_pending_review
- A weakness in a system, application, or network that is subject to exploitation or misuse.
- §1
- Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited by a threat source.
- §1
- Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
- §1
- Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
- §1
- Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
- §1
- Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
- §1
- Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
- §1
- Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.
- §1
- A weakness in a system, application, or network that is subject to exploitation or misuse.
- §1
- susceptibility to injury or attack
- §2
- the state of being vulnerable or exposed
- §1 · glossary
- Weakness in a component of a system, particularly information assets, system security procedures, internal controls, or implementation, that could be exploited or triggered by human action or natural events.Attribution from the CKI glossary mapping stage (glossary)
- §1 · legacy_primary
- Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.DR-088 backfill from the noun definition column
Outgoing relationships
No outgoing triples
This term is not the subject of any RDF-style relationship yet.
Incoming relationships
- related
- ←weaknessnoun