The following vulnerability severity levels are used
to categorize the vulnerabilities:
CRITICAL PROBLEMS
Vulnerabilities which pose an immediate threat to the
network by allowing a remote attacker to directly gain read
or write access, execute commands on the target, or create
a denial of service.
AREAS OF CONCERN
Vulnerabilities which do not directly allow remote
access, but do allow privilege elevation attacks, attacks on
other targets using the vulnerable host as an intermediary,
or gathering of passwords or configuration information which
could be used to plan an attack.
POTENTIAL PROBLEMS
Warnings which may or may not be vulnerabilities,
depending upon the patch level or configuration of the
target. Further investigation on the part of the system
administrator may be necessary.
SERVICES
Network services which accept client connections on
a given TCP or UDP port. This is simply a count of network
services, and does not imply that the service is or is not
vulnerable.