Exploitability Metrics
Is there any special precondition, or this can be exploited during normal operation?
Impact Metrics
Reveals any sensitive information - user data, crypto keys, source code
Allows for standard operation disruption. (e.g. message injection)
Disturbs the function of the system/unit (e.g. ECU reset)