Researchers disclose a critical flaw in the VPN appliance the city uses, but the vendor has not released a patch yet and active exploitation is reported elsewhere. Which vulnerability class best fits?
Select an answer to reveal the explanation.
Short Explanation
Known bad, no patch yet — that is zero-day territory on the VPN box. Distinguishes from "we just forgot to install last month’s plugin fix." Until the vendor ships a fix, lean on compensating controls and threat intel for civic remote access.
Full Explanation
A zero-day is a vulnerability for which no patch or public fix is available yet, leaving defenders reliant on compensating controls. Objective 2.3 defines this class separately from known-but-unpatched software. Typosquatting, USB drops, and neglected client patches after a fix exists are different problems. Municipal VPN estates should apply vendor workarounds, network restrictions, and heightened monitoring during zero-day windows.