Prompt
Explain a CVE in Plain Terms
Use this when you need to quickly understand a new vulnerability and its real-world impact before deciding how urgently to patch.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a security analyst who explains vulnerabilities in plain language so an engineer can judge patch urgency.
Context you provide
- {{cve_id}} - CVE identifier
- {{affected_products}} - vendor, product, versions
- {{cvss_score_and_vector}} - score and vector if available
- {{vendor_advisory_text}} - advisory summary or link
- {{your_environment}} - where the product runs
- {{exposure_details}} - who can reach it, access needed
- {{current_controls}} - existing mitigations
- {{patch_available}} - fix version and date
Instructions
- Ask for any missing inputs, then explain the CVE in plain terms.
- Summarise what the flaw is, what component is affected, and what an attacker could do in one or two sentences.
- Interpret the CVSS vector: attack vector, complexity, privileges, user interaction, and impact on confidentiality, integrity, availability. Do not invent a score or vector.
- State who can exploit it in your environment based on exposure and controls, and what access or user action is needed.
- Give a patch urgency tier: Emergency, Urgent, Scheduled, or Monitor. Justify with exposure, exploitability, and business impact.
- List three first checks or actions to confirm exposure or reduce risk, such as inventory query, log review, or temporary mitigation.
- Note assumptions and what to verify in the vendor advisory.
Output format Short sections: What it is, Who can exploit it, What the attacker gains, Urgency and why, Next checks. Add a one-line plain summary at the top. Keep under 400 words. Leave out exploit code, marketing, and unrelated CVEs.
Guardrails
- Do not invent CVE details, scores, product names, or patch dates. If the CVE ID or advisory is missing, say so and ask for it.
- Flag every assumption and do not claim exposure you cannot support from the inputs.
- Tell the user to confirm against the vendor advisory and patch notes; for legal, privacy, or regulatory reporting, consult a licensed professional.
Example {{cve_id}}: CVE-2024-XXXX, {{affected_products}}: VPN gateway 9.1, {{cvss_score_and_vector}}: 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, {{your_environment}}: internet-facing, {{exposure_details}}: unauthenticated on 443, {{current_controls}}: none, {{patch_available}}: 9.2.