ThreatSabre Docs
Concept Guide

Risk Ratings

Understanding ThreatSabre risk ratings, exposure thresholds, attack surface coverage, vulnerability scoring, and configuration issue assessment for Fortinet devices.

What Risk Ratings Mean in ThreatSabre

Throughout ThreatSabre risks are rated into five categories:

Risk CategoryMeaning
CriticalImmediate action required - actively exploitable or high-impact exposure
HighPrompt attention needed - significant security concern
MediumShould be addressed - moderate security concern
LowMinor concern - address when convenient
Info/NoneInformational only - no action required

Exposure thresholds

By default ThreatSabre uses the following thresholds for determining exposure.

ExposureThreshold (ipv4)Notes
Exposed to Full internet> 3.6 Billion Public IPsAssumes full internet with no filtering for malicious IPs or high risk geos
Exposed to Internet> 1024 Public IPs or Dynamic Source (i.e. External Threat Feed)Assumes full internet with basic filtering
Exposed to Private Networks> 64 Private IPsAssumes exposure to private networks
Exposed to Limited Untrusted Networks> 0 Untrusted IPsExposed to Untrusted IPs but not exposed to enough private or public IPs to assume wide spread exposure
Exposed to Trusted IPs> 0 Trusted IPsLocked down to only trusted IPs (configured in the ThreatSabre platform)
NoneService Disabled / No AccessService is disabled or all interfaces are down or denied via local-in policy

These thresholds are currently hardcoded but may be user defined in the future if there is demand and legitimate use cases to have these user defined.

Exposed to Full internet threshold was changed from 4 Billion to 3.6 Billion in an update on 2026-05-15. This was due to removal of non-routable ip's such as 0.0.0.0/8 from the pool of IP addressing counted as public.

Attack Surface Ratings

ThreatSabre has three categories for attack surfaces which affect how they are rated.

CategoryDescriptionAttack Surfaces
AdminServices used to administer the device, should be locked down to only trusted management IP addressesHTTP Admin Interface, HTTPS Admin Interface, RADIUS Accounting, SSH Admin Interface, TELNET Interface
IntegrationServices used for Integration, should be locked down to known IP addressesBGP Interface, FGFM Interface, Security Fabric Connection, SNMP Interface
PublicServices which require exposure to the public internet for their primary function, should block known bad IP addressesFortiToken Mobile Interface, IPSEC VPN Interface, SSLVPN Interface

Admin Risk Rating

Risk RatingExposure
CriticalExposed to Full internet, Exposed to Internet
HighExposed to Private Networks
MediumExposed to Limited Untrusted Networks
LowExposed to Trusted IPs
InfoNone

Integration Risk Rating

Risk RatingExposure
CriticalExposed to Full internet
HighExposed to Internet
MediumExposed to Private Networks, Exposed to Limited Untrusted Networks
LowExposed to Trusted IPs
InfoNone

Public Risk Rating

Risk RatingExposure
Criticaln/a
HighExposed to Full internet
MediumExposed to Internet
LowExposed to Private Networks, Exposed to Limited Untrusted Networks, Exposed to Trusted IPs
InfoNone

Vulnerability Ratings

The ThreatSabre rating system is inspired by other systems such as CVSS but takes into consideration the additional context that ThreatSabre has such as mitigations that might be in place (i.e. vulnerable feature is disabled, vulnerable feature is locked down to trusted hosts)

Vulnerabilities are rated based on:

Static Categories:

  • Impact (I): The potential impact of a Vulnerability (High/Medium/Low)
  • Authentication (A): Does the attacker need to be authenticated to the system to exploit the vulnerability (Privileged, Non-Privileged, User, None)
  • Complexity (C): Is user interaction or specific condition required for exploit (High/Medium/Low)

Dynamic Categories:

  • Exposure (E): What attack surface is exposed for the vulnerability (Public, Private, Trusted, N/A)
  • Mitigation (M): Does the specific device configuration allow for the vulnerability to be exploited (Full/Partial/None)

Examples:
FG-IR-25-084 / CVE-2025-25249
Fortinet CVSS 3.1 Score: 7.4 [HIGH] | NIST NVD CVSS 3.1 Score: 9.8 [CRITICAL] | NIST CNA CVSS 3.1 Score: 8.1 [HIGH]

  • Impact: Impact is Remote Code Execution - HIGH
  • Authentication: No authentication requirements are noted - None
  • Complexity: No detail is provided as to any mitigating conditions - Low
  • Exposure: It is stated that an interface needs to be configured with fabric access, ThreatSabre considers what exposure these interfaces have.
  • Mitigation: It is stated that a full mitigation/workaround can be applied by disabling fabric interfaces.

For the Static Categories, this vulnerability is categorized as: Impact: High | Authentication: None | Complexity: Low

  • Full Mitigation is in place: Final Rating = Low
  • No Mitigation and Exposed to Public Internet = Critical
  • No Mitigation and Exposed to Private Networks = High
  • No Mitigation and Exposed to Trusted Networks = Medium

Configuration Issue Ratings

Exact definitions for Configuration Issue Ratings are still being reviewed with community feedback.

For configuration and policy issues ThreatSabre brings in aspects of best practice and confidence about the configuration.

For example:

  • Admin interface exposed to internet - This is universally agreed to be bad practice and ThreatSabre is highly confident about the impact. This is rated as Critical
  • VIP for TCP/3000 exposed to internet - There are very few good reasons why web development ports should be exposed to the internet but there may be legitimate reasons. This is rated as High
  • No 2FA on a local user with VPN access - It is best practice to have 2FA enabled but there may be legitimate reasons for some users to not have it enabled. This is rated as Medium
  • USB auto-config enabled - While Fortinet best practice is to disable this, it is commonly used for provisioning or service restoration. As long as the device is physically secure, this is acceptable. This is rated as Low

Lifecycle Risk

Support Expiry

Expires InSeverityDisplay
>= 90 DaysINFOActive
< 90 DaysLOWExpires Soon
< 60 DaysMEDIUMExpires Soon
< 30 DaysHIGHExpires Soon
< 7 DaysCRITICALExpires Soon
< 0 DaysCRITICALExpired

Software Status

StatusSeverity
GA (General Availability)INFO
EOES (End of Engineering Support)MEDIUM
FFR (Final Firmware Release)High
EOS (End of Suport)CRITICAL

Hardware Status

StatusSeverity
GA (General Availability)INFO
EOO (End of Order)LOW
LSED (Last Service Extension Date)High
EOS (End of Suport)CRITICAL

On this page