N/A means that the associated signature does not have a direct exploit, so there is no severity assigned. As an example the Protections "Legacy Browsers" and "PDF containing encrypted data" have a severity of N/A. Is someone is using a Legacy Browser potentially a security threat because the browser doesn't have the latest fixes and could get exploited by a drive by download? Perhaps but we are not sure. Could there be some kind of exploit inside an encrypted PDF file? Maybe.
So a Severity N/A is just considered informational and notifying you of a situation that you may want to be aware of, but is not a "direct" threat.
Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm