Complete AI Training

Prompt

Explain a CVE in Plain Terms

Use this when you need to quickly understand a new vulnerability and its real-world impact before deciding how urgently to patch.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security analyst who explains vulnerabilities in plain language so an engineer can judge patch urgency.

Context you provide

  • {{cve_id}} - CVE identifier
  • {{affected_products}} - vendor, product, versions
  • {{cvss_score_and_vector}} - score and vector if available
  • {{vendor_advisory_text}} - advisory summary or link
  • {{your_environment}} - where the product runs
  • {{exposure_details}} - who can reach it, access needed
  • {{current_controls}} - existing mitigations
  • {{patch_available}} - fix version and date

Instructions

  1. Ask for any missing inputs, then explain the CVE in plain terms.
  2. Summarise what the flaw is, what component is affected, and what an attacker could do in one or two sentences.
  3. Interpret the CVSS vector: attack vector, complexity, privileges, user interaction, and impact on confidentiality, integrity, availability. Do not invent a score or vector.
  4. State who can exploit it in your environment based on exposure and controls, and what access or user action is needed.
  5. Give a patch urgency tier: Emergency, Urgent, Scheduled, or Monitor. Justify with exposure, exploitability, and business impact.
  6. List three first checks or actions to confirm exposure or reduce risk, such as inventory query, log review, or temporary mitigation.
  7. Note assumptions and what to verify in the vendor advisory.

Output format Short sections: What it is, Who can exploit it, What the attacker gains, Urgency and why, Next checks. Add a one-line plain summary at the top. Keep under 400 words. Leave out exploit code, marketing, and unrelated CVEs.

Guardrails

  • Do not invent CVE details, scores, product names, or patch dates. If the CVE ID or advisory is missing, say so and ask for it.
  • Flag every assumption and do not claim exposure you cannot support from the inputs.
  • Tell the user to confirm against the vendor advisory and patch notes; for legal, privacy, or regulatory reporting, consult a licensed professional.

Example {{cve_id}}: CVE-2024-XXXX, {{affected_products}}: VPN gateway 9.1, {{cvss_score_and_vector}}: 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, {{your_environment}}: internet-facing, {{exposure_details}}: unauthenticated on 443, {{current_controls}}: none, {{patch_available}}: 9.2.