Causal model
What has to happen for this consequence to hold?
1 candidate path · explicit source, inference, and assumption boundaries.
Recovery · Dominant path
Device availability and recovery
Unauthenticated pairing requests can disrupt the head-worn AR overlay during use, creating a bounded availability and situational-awareness problem rather than persistent control.
Network-reachable without prior access
Network-reachable, without authentication, no user interaction (gated only by whether Device Portal is enabled and reachable, but per rule position is internet and default-exposed-style network reachability).
EvidenceNVD
Single bounded transition
Availability loss is not a reusable cross-domain authority bridge.
EvidenceNo direct citation — inspect the declared inference or assumption.
Operational safety effect
Unauthenticated pairing requests can disrupt the head-worn AR overlay during use, creating a bounded availability and situational-awareness problem rather than persistent control.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device availability and recovery
Unauthenticated pairing requests can disrupt the head-worn AR overlay during use, creating a bounded availability and situational-awareness problem rather than persistent control.
EvidenceNo direct citation — inspect the declared inference or assumption.
Routine local recovery
Stopping the request flood and rebooting the headset restores service; no fleet reprovisioning or key rotation is required.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
Network-reachable, without authentication, no user interaction (gated only by whether Device Portal is enabled and reachable, but per rule position is internet and default-exposed-style network reachability).
- Execution complexity
EC 4 - Straightforward operation
A straightforward request flood is sufficient once the Device Portal is reachable; no memory-corruption exploit is needed.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 2 - Operational safety effect
Unauthenticated pairing requests can disrupt the head-worn AR overlay during use, creating a bounded availability and situational-awareness problem rather than persistent control.
- Data / perception
DP 0 - No data consequence
The request flood affects service availability without independently exposing stored or streamed user data.
- Authority
AT 0 - No authority gained
The attacker can exhaust the pairing service but does not gain an authenticated session or broader device authority.
Scale and recovery
- Chainability
CH 1 - Single bounded transition
Availability loss is not a reusable cross-domain authority bridge.
- Reuse scale
SR 2 - Repeatable method
The same request pattern can be reused against HoloLens devices that expose the vulnerable portal service.
- Execution scale
SX 3 - Deployment-wide with setup
The attacker must direct traffic at each reachable headset; the weakness does not provide a fleet-wide execution channel.
- Recovery burden
OR 1 - Routine local recovery
Stopping the request flood and rebooting the headset restores service; no fleet reprovisioning or key rotation is required.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Unauthenticated pairing requests can disrupt the head-worn AR overlay during use, creating a bounded availability and situational-awareness problem rather than persistent control.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:4/EX:4/PH:2/DP:0/AT:0/CH:1/SR:2/SX:3/OR:1/EV:2/LS:PATCH_AVAILABLERead the scoring method →Triage implication
Verify the recovery transition before acting on the band.
Validate each modeled transition and recovery assumption before using the candidate band as a remediation decision.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HCVE recordsCVE-2024-57972
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses HoloLens Device Portal pairing-API unauthenticated DoS (CVE-2024-57972) at CRITICAL — the worst of 1 risk path (safety). The dominant consequence is denial of a device function.
Vulnerability
HoloLens Device Portal pairing-API unauthenticated DoS (CVE-2024-57972). Reported attack vector: NETWORK (HTTP to Device Portal pairing API), no auth, no user interaction.
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_AVAILABILITY → CRITICAL
CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:4/EX:4/PH:2/DP:0/AT:0/CH:1/SR:2/SX:3/OR:1/EV:2/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=ELEVATED · AT=ELEVATED → base CRITICAL → assessed CRITICAL.
- Unauthenticated HTTP flood of the Device Portal pairing API exhausts resources and renders the HoloLens unresponsive until the flood stops or the device reboots. RE:4 network-reachable, no auth, no user interaction (gated only by whether Device Portal is enabled/reachable, but per rule position is internet/default-exposed-style network reachability). EC:4 trivial single-vector commodity flood. AT:0 no privilege/code-execution/authority gain, pure resource exhaustion. PH:2 availability disruption of head-worn AR overlay mid-use is a usability/safety nuisance but no actuation, wrong therapy, or persistent harm; device recovers on reboot - not credible injury so not PH:3/4. DP:0 no confidentiality/integrity impact. CH:1 availability loss is not a reusable cross-domain authority bridge. SR:2 the technique (no per-device secret) is reusable across the device class but no shared key/credential/signing-root is captured (not SR:4). SX:3 a script can sweep many reachable HoloLens devices deployment-wide, but each requires a reachable network position and effect is transient per device - not true fleet-scale cloud/supply-chain remote (SX:4). OR:1 recovery is a simple reboot / stop-the-flood, no fleet reprovision or key rotation needed; patch available. EV:2 report-backed (CVE advisory, not independently reproduced here). LS PATCH_AVAILABLE.
- boundary_crossing — true: crosses network->device(app/service)->physical-use boundary. No actuation/perception feeding action, so perception_feeds_action=false; recovery_needs_fleet_action=false;
- active_exploitation — false (no known in-the-wild exploitation).
Published baseline
- v3.1 6.5 MEDIUM —
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H— MITRE via NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0015 (“HoloLens Device Portal pairing-API unauthenticated DoS (CVE-2024-57972)”), paths.cfse.ai/CPATH-2026-0015 (published 2026-06-03).