...
- severity - how serious are the consequences of the rule being ignored;
1 = low (denial-of-service attack, abnormal termination)
2 = medium (data integrity violation, unintentional information disclosure)
3 = high (run arbitrary code)
...
...
...