Purpose and evidence boundary

Measure the consequence the exploit can reach.

CFSE Consequence Paths is a public vulnerability registry model. It asks which boundary is crossed, what capability is gained, which terminal consequence becomes reachable, how far it scales, and what recovery requires.

It does not estimate exploitation likelihood, and it does not prescribe remediation priority for a specific deployment.

Unit of analysis
One consequence path
Claim bases
3 explicit labels
Published authority
Registry record

Claim boundaries

Follow the argument, step by step.

The path records how the score was reached. Every transition carries one of three labels so readers can distinguish published evidence from modeled reasoning.

01

Source-backed

A claim attributed to a named public source and linked to that source.

02

Model inference

A transition derived from source facts by applying the published method.

03

Operational assumption

A deployment, scale, guard, or recovery condition required for the path.

Not metric fields

Nine model design requirements.

These are failure modes the model must resist. They explain why the model exists; the actual vector fields and scoring rules are documented separately.

  1. 01

    Blast radius is a property of the path

    Distinguish one-device execution from a credential, artifact, or control-plane primitive that can be reused across a deployment.

  2. 02

    Chains stay composed

    Keep the remote leak, local payload, boundary crossing, and terminal consequence in one inspectable argument instead of scoring isolated fragments.

  3. 03

    Credentials and control primitives transfer authority

    Treat a shipped credential, engineering backdoor, root primitive, or signing bypass as an authority failure, even when the first observation looks like disclosure.

  4. 04

    Device class does not determine consequence

    A medical or robotic product does not make every weakness catastrophic. Consequence must follow from the reachable capability, not the product label.

  5. 05

    Missing controls affect detection and recovery

    Insufficient logging or monitoring slows detection, investigation, and recovery after a separate compromise.

  6. 06

    Preserve evidence boundaries

    Keep sourced facts, model inferences, and operational assumptions distinct so the score reflects the actual basis of each step.

  7. 07

    Score the documented mechanics

    Use the documented behavior and deployment path. Disregard vendor origin, dramatic framing, and disclosure rhetoric.

  8. 08

    Recovery changes the consequence

    A hotfixable service, per-device reflash, fleet reprovision, trust-root rotation, and physical recall impose materially different burdens.

  9. 09

    Representations can leak sensitive state

    A sanctioned output can preserve enough structure to infer a protected input. Sensor privacy includes informative avatars, renderings, predictions, and actuated outputs.

Use boundaries

Model scope and limits

Modeled here
  • Decompose a vulnerability into distinct terminal consequences.
  • Expose source, inference, and assumption boundaries.
  • Represent authority, perception, safety, privacy, systemic, and recovery paths.
  • Retain published scores as comparison baselines.
Outside this model
  • Exploitation likelihood.
  • Deployment-specific asset and safety analysis.
  • Remediation priority.
  • Empirical accuracy or inter-rater reliability claims.