IronSights

Penetration testing

Vulnerability

A weakness in a system, application, or process that could be exploited by an attacker to gain unauthorised access, cause disruption, or achieve other malicious objectives.

Also known assecurity vulnerabilitysecurity flawsecurity weakness

In plain English

A vulnerability is any flaw that an attacker could use to their advantage. This ranges from unpatched software with a published exploit, to a misconfigured firewall rule, to a process that relies on users never making a mistake. Not all vulnerabilities are equally exploitable — risk ratings account for the likelihood of exploitation and the potential impact.

Keep learning

More terms in the IronSights Glossary.