A controller vulnerability for the municipal WLAN requires valid administrator credentials before it can be exploited. How should that affect remote risk relative to an unauthenticated wireless exploit?
Select an answer to reveal the explanation.
Short Explanation
If the attacker already needs the keys to the kingdom, the bug is still real—but it is not the same as an unauthenticated wireless free-for-all. Privilege needed dials the remote-risk story down a notch.
Full Explanation
Privileges required for exploitation are a primary factor in risk rating. Vulnerabilities that presuppose administrator credentials present different remote exposure than unauthenticated wireless exploits. Privilege requirements do not invalidate the CVE, but they change comparative risk versus unauthenticated paths.