Source-backed
A claim attributed to a named public source and linked to that source.
Purpose and evidence boundary
CFSE Consequence Paths is a public vulnerability registry model. It asks which boundary is crossed, what capability is gained, which terminal consequence becomes reachable, how far it scales, and what recovery requires.
It does not estimate exploitation likelihood, and it does not prescribe remediation priority for a specific deployment.
Claim boundaries
The path records how the score was reached. Every transition carries one of three labels so readers can distinguish published evidence from modeled reasoning.
A claim attributed to a named public source and linked to that source.
A transition derived from source facts by applying the published method.
A deployment, scale, guard, or recovery condition required for the path.
Not metric fields
These are failure modes the model must resist. They explain why the model exists; the actual vector fields and scoring rules are documented separately.
Distinguish one-device execution from a credential, artifact, or control-plane primitive that can be reused across a deployment.
Keep the remote leak, local payload, boundary crossing, and terminal consequence in one inspectable argument instead of scoring isolated fragments.
Treat a shipped credential, engineering backdoor, root primitive, or signing bypass as an authority failure, even when the first observation looks like disclosure.
A medical or robotic product does not make every weakness catastrophic. Consequence must follow from the reachable capability, not the product label.
Insufficient logging or monitoring slows detection, investigation, and recovery after a separate compromise.
Keep sourced facts, model inferences, and operational assumptions distinct so the score reflects the actual basis of each step.
Use the documented behavior and deployment path. Disregard vendor origin, dramatic framing, and disclosure rhetoric.
A hotfixable service, per-device reflash, fleet reprovision, trust-root rotation, and physical recall impose materially different burdens.
A sanctioned output can preserve enough structure to infer a protected input. Sensor privacy includes informative avatars, renderings, predictions, and actuated outputs.
Use boundaries