CPATH-2026-0015 · Smart glasses / AR

HoloLens Device Portal pairing-API unauthenticated DoS (CVE-2024-57972)

A dominant device availability and recovery path connects the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Dominant pathDevice availability and recovery

This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL.

Causal model

What has to happen for this consequence to hold?

1 candidate path · explicit source, inference, and assumption boundaries.

Recovery · Dominant path

Device availability and recovery

Unauthenticated pairing requests can disrupt the head-worn AR overlay during use, creating a bounded availability and situational-awareness problem rather than persistent control.

CRITICAL
  1. accessSource-backed

    Network-reachable without prior access

    Network-reachable, without authentication, no user interaction (gated only by whether Device Portal is enabled and reachable, but per rule position is internet and default-exposed-style network reachability).

    EvidenceNVD

  2. boundaryModel inference

    Single bounded transition

    Availability loss is not a reusable cross-domain authority bridge.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Operational safety effect

    Unauthenticated pairing requests can disrupt the head-worn AR overlay during use, creating a bounded availability and situational-awareness problem rather than persistent control.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device availability and recovery

    Unauthenticated pairing requests can disrupt the head-worn AR overlay during use, creating a bounded availability and situational-awareness problem rather than persistent control.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Routine local recovery

    Stopping the request flood and rebooting the headset restores service; no fleet reprovisioning or key rotation is required.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

Network-reachable, without authentication, no user interaction (gated only by whether Device Portal is enabled and reachable, but per rule position is internet and default-exposed-style network reachability).

Source-backedNVD
Execution complexityEC 4
Straightforward operation

A straightforward request flood is sufficient once the Device Portal is reachable; no memory-corruption exploit is needed.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Unauthenticated pairing requests can disrupt the head-worn AR overlay during use, creating a bounded availability and situational-awareness problem rather than persistent control.

Model inference
Data / perceptionDP 0
No data consequence

The request flood affects service availability without independently exposing stored or streamed user data.

Model inference
AuthorityAT 0
No authority gained

The attacker can exhaust the pairing service but does not gain an authenticated session or broader device authority.

Model inference
Scale and recovery
ChainabilityCH 1
Single bounded transition

Availability loss is not a reusable cross-domain authority bridge.

Model inference
Reuse scaleSR 2
Repeatable method

The same request pattern can be reused against HoloLens devices that expose the vulnerable portal service.

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

The attacker must direct traffic at each reachable headset; the weakness does not provide a fleet-wide execution channel.

Operational assumption
Recovery burdenOR 1
Routine local recovery

Stopping the request flood and rebooting the headset restores service; no fleet reprovisioning or key rotation is required.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Unauthenticated pairing requests can disrupt the head-worn AR overlay during use, creating a bounded availability and situational-awareness problem rather than persistent control.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:4/EX:4/PH:2/DP:0/AT:0/CH:1/SR:2/SX:3/OR:1/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the recovery transition before acting on the band.

Validate each modeled transition and recovery assumption before using the candidate band as a remediation decision.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 6.5 MEDIUMMITRE via NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses HoloLens Device Portal pairing-API unauthenticated DoS (CVE-2024-57972) at CRITICAL — the worst of 1 risk path (safety). The dominant consequence is denial of a device function.

Vulnerability

HoloLens Device Portal pairing-API unauthenticated DoS (CVE-2024-57972). Reported attack vector: NETWORK (HTTP to Device Portal pairing API), no auth, no user interaction.

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_AVAILABILITYCRITICAL

CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:4/EX:4/PH:2/DP:0/AT:0/CH:1/SR:2/SX:3/OR:1/EV:2/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=ELEVATED · AT=ELEVATED → base CRITICAL → assessed CRITICAL.

  • Unauthenticated HTTP flood of the Device Portal pairing API exhausts resources and renders the HoloLens unresponsive until the flood stops or the device reboots. RE:4 network-reachable, no auth, no user interaction (gated only by whether Device Portal is enabled/reachable, but per rule position is internet/default-exposed-style network reachability). EC:4 trivial single-vector commodity flood. AT:0 no privilege/code-execution/authority gain, pure resource exhaustion. PH:2 availability disruption of head-worn AR overlay mid-use is a usability/safety nuisance but no actuation, wrong therapy, or persistent harm; device recovers on reboot - not credible injury so not PH:3/4. DP:0 no confidentiality/integrity impact. CH:1 availability loss is not a reusable cross-domain authority bridge. SR:2 the technique (no per-device secret) is reusable across the device class but no shared key/credential/signing-root is captured (not SR:4). SX:3 a script can sweep many reachable HoloLens devices deployment-wide, but each requires a reachable network position and effect is transient per device - not true fleet-scale cloud/supply-chain remote (SX:4). OR:1 recovery is a simple reboot / stop-the-flood, no fleet reprovision or key rotation needed; patch available. EV:2 report-backed (CVE advisory, not independently reproduced here). LS PATCH_AVAILABLE.
  • boundary_crossing — true: crosses network->device(app/service)->physical-use boundary. No actuation/perception feeding action, so perception_feeds_action=false; recovery_needs_fleet_action=false;
  • active_exploitation — false (no known in-the-wild exploitation).

Published baseline

  • v3.1 6.5 MEDIUM — CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H — MITRE via NVD

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0015 (“HoloLens Device Portal pairing-API unauthenticated DoS (CVE-2024-57972)”), paths.cfse.ai/CPATH-2026-0015 (published 2026-06-03).