Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a vulnerability?

A vulnerability is a weakness in software, hardware, configuration, process or design that can permit unintended activity. It establishes a possible route or capability, not proof that anyone used it.

Weaknesses include coding flaws, insecure defaults, excessive permissions, weak authentication, exposed interfaces and failures of isolation. Some have public identifiers; others depend on a particular configuration or workflow.

WeaknessWhat condition existed?Version, configuration, permission or design state.
PrerequisitesWhat was needed to reach it?Network access, authentication, user action or prior privilege.
CapabilityWhat could the weakness allow?Access, execution, data exposure or another unintended effect.
Incident evidenceWas it actually used?Requests, processes, files, account changes or data access.

Establish the vulnerable condition

Identify the component, version and configuration at the relevant time. Define the preconditions: whether an attacker needed network reachability, authentication, user action or another level of access. Then state the access or effect the weakness could provide.

Preserve version, patch, exposure and configuration records before response changes the system. A later scanner result describes the examined state and may not prove what existed during the incident.

Separate opportunity from use

A system can remain vulnerable without being exploited, and an incident can enter through another route. Look for matching requests, authentication changes, process activity, files or data access before concluding that the weakness explains the compromise.

A patch applied after discovery is not evidence of earlier exploitation; it may be precautionary. For named product flaws, record the contemporaneous vendor or authoritative guidance, because affected versions, prerequisites and assessments can change.

Key takeaway

Vulnerability evidence shows that a weakness and opportunity existed; incident-specific records are needed to prove exploitation and effect.

Reference: CIM-093Cyber Incidents & Offender Methods