Risk Ratings
Understanding ThreatSabre risk ratings, exposure thresholds, attack surface coverage, vulnerability scoring, and configuration issue assessment for Fortinet devices.
What Risk Ratings Mean in ThreatSabre
Throughout ThreatSabre risks are rated into five categories:
| Risk Category | Meaning |
|---|---|
| Critical | Immediate action required - actively exploitable or high-impact exposure |
| High | Prompt attention needed - significant security concern |
| Medium | Should be addressed - moderate security concern |
| Low | Minor concern - address when convenient |
| Info/None | Informational only - no action required |
Exposure thresholds
By default ThreatSabre uses the following thresholds for determining exposure.
| Exposure | Threshold (ipv4) | Notes |
|---|---|---|
| Exposed to Full internet | > 3.6 Billion Public IPs | Assumes full internet with no filtering for malicious IPs or high risk geos |
| Exposed to Internet | > 1024 Public IPs or Dynamic Source (i.e. External Threat Feed) | Assumes full internet with basic filtering |
| Exposed to Private Networks | > 64 Private IPs | Assumes exposure to private networks |
| Exposed to Limited Untrusted Networks | > 0 Untrusted IPs | Exposed to Untrusted IPs but not exposed to enough private or public IPs to assume wide spread exposure |
| Exposed to Trusted IPs | > 0 Trusted IPs | Locked down to only trusted IPs (configured in the ThreatSabre platform) |
| None | Service Disabled / No Access | Service is disabled or all interfaces are down or denied via local-in policy |
These thresholds are currently hardcoded but may be user defined in the future if there is demand and legitimate use cases to have these user defined.
Exposed to Full internet threshold was changed from 4 Billion to 3.6 Billion in an update on 2026-05-15. This was due to removal of non-routable ip's such as 0.0.0.0/8 from the pool of IP addressing counted as public.
Attack Surface Ratings
ThreatSabre has three categories for attack surfaces which affect how they are rated.
| Category | Description | Attack Surfaces |
|---|---|---|
| Admin | Services used to administer the device, should be locked down to only trusted management IP addresses | HTTP Admin Interface, HTTPS Admin Interface, RADIUS Accounting, SSH Admin Interface, TELNET Interface |
| Integration | Services used for Integration, should be locked down to known IP addresses | BGP Interface, FGFM Interface, Security Fabric Connection, SNMP Interface |
| Public | Services which require exposure to the public internet for their primary function, should block known bad IP addresses | FortiToken Mobile Interface, IPSEC VPN Interface, SSLVPN Interface |
Admin Risk Rating
| Risk Rating | Exposure |
|---|---|
| Critical | Exposed to Full internet, Exposed to Internet |
| High | Exposed to Private Networks |
| Medium | Exposed to Limited Untrusted Networks |
| Low | Exposed to Trusted IPs |
| Info | None |
Integration Risk Rating
| Risk Rating | Exposure |
|---|---|
| Critical | Exposed to Full internet |
| High | Exposed to Internet |
| Medium | Exposed to Private Networks, Exposed to Limited Untrusted Networks |
| Low | Exposed to Trusted IPs |
| Info | None |
Public Risk Rating
| Risk Rating | Exposure |
|---|---|
| Critical | n/a |
| High | Exposed to Full internet |
| Medium | Exposed to Internet |
| Low | Exposed to Private Networks, Exposed to Limited Untrusted Networks, Exposed to Trusted IPs |
| Info | None |
Vulnerability Ratings
The ThreatSabre rating system is inspired by other systems such as CVSS but takes into consideration the additional context that ThreatSabre has such as mitigations that might be in place (i.e. vulnerable feature is disabled, vulnerable feature is locked down to trusted hosts)
Vulnerabilities are rated based on:
Static Categories:
- Impact (I): The potential impact of a Vulnerability (High/Medium/Low)
- Authentication (A): Does the attacker need to be authenticated to the system to exploit the vulnerability (Privileged, Non-Privileged, User, None)
- Complexity (C): Is user interaction or specific condition required for exploit (High/Medium/Low)
Dynamic Categories:
- Exposure (E): What attack surface is exposed for the vulnerability (Public, Private, Trusted, N/A)
- Mitigation (M): Does the specific device configuration allow for the vulnerability to be exploited (Full/Partial/None)
Examples:
FG-IR-25-084 / CVE-2025-25249
Fortinet CVSS 3.1 Score: 7.4 [HIGH] | NIST NVD CVSS 3.1 Score: 9.8 [CRITICAL] | NIST CNA CVSS 3.1 Score: 8.1 [HIGH]
- Impact: Impact is Remote Code Execution - HIGH
- Authentication: No authentication requirements are noted - None
- Complexity: No detail is provided as to any mitigating conditions - Low
- Exposure: It is stated that an interface needs to be configured with fabric access, ThreatSabre considers what exposure these interfaces have.
- Mitigation: It is stated that a full mitigation/workaround can be applied by disabling fabric interfaces.
For the Static Categories, this vulnerability is categorized as: Impact: High | Authentication: None | Complexity: Low
- Full Mitigation is in place: Final Rating = Low
- No Mitigation and Exposed to Public Internet = Critical
- No Mitigation and Exposed to Private Networks = High
- No Mitigation and Exposed to Trusted Networks = Medium
Configuration Issue Ratings
Exact definitions for Configuration Issue Ratings are still being reviewed with community feedback.
For configuration and policy issues ThreatSabre brings in aspects of best practice and confidence about the configuration.
For example:
- Admin interface exposed to internet - This is universally agreed to be bad practice and ThreatSabre is highly confident about the impact. This is rated as Critical
- VIP for TCP/3000 exposed to internet - There are very few good reasons why web development ports should be exposed to the internet but there may be legitimate reasons. This is rated as High
- No 2FA on a local user with VPN access - It is best practice to have 2FA enabled but there may be legitimate reasons for some users to not have it enabled. This is rated as Medium
- USB auto-config enabled - While Fortinet best practice is to disable this, it is commonly used for provisioning or service restoration. As long as the device is physically secure, this is acceptable. This is rated as Low
Lifecycle Risk
Support Expiry
| Expires In | Severity | Display |
|---|---|---|
| >= 90 Days | INFO | Active |
| < 90 Days | LOW | Expires Soon |
| < 60 Days | MEDIUM | Expires Soon |
| < 30 Days | HIGH | Expires Soon |
| < 7 Days | CRITICAL | Expires Soon |
| < 0 Days | CRITICAL | Expired |
Software Status
| Status | Severity |
|---|---|
| GA (General Availability) | INFO |
| EOES (End of Engineering Support) | MEDIUM |
| FFR (Final Firmware Release) | High |
| EOS (End of Suport) | CRITICAL |
Hardware Status
| Status | Severity |
|---|---|
| GA (General Availability) | INFO |
| EOO (End of Order) | LOW |
| LSED (Last Service Extension Date) | High |
| EOS (End of Suport) | CRITICAL |