01 Reachable consequence What terminal state does attacker-controlled input actually reach? Physical action or therapy The flaw can influence motion, therapy, dosing, pressure, heat, or another embodied process. Metrics set PH=4 · RE=2 · EC=3 · DP=2 · AT=3 · CH=3False perception drives action Manipulated sensor, model, image, or state data can drive navigation, clinical, or control decisions. Metrics set PH=4 · RE=3 · EC=3 · DP=4 · AT=2 · CH=3Firmware, signing, or trust root The path can persist, replace code, bypass update trust, or compromise a root authority. Metrics set PH=3 · RE=2 · EC=3 · DP=3 · AT=4 · CH=4Cloud, account, or fleet authority The attacker reaches management authority over many devices or a vendor/control-plane path. Metrics set PH=0 · RE=4 · EC=3 · DP=3 · AT=4 · CH=4Account or administrative authority The path reaches an account, session, service, or administrative authority boundary. Metrics set PH=0 · RE=3 · EC=4 · DP=3 · AT=3 · CH=3Data or privacy only The main consequence is exposure of data, identity, or private environment state. Metrics set PH=0 · RE=2 · EC=3 · DP=3 · AT=1 · CH=1Sensor or representation privacy A sensor stream, biometric, gaze signal, spatial map, or representation exposes sensitive state. Metrics set PH=0 · RE=2 · EC=3 · DP=4 · AT=1 · CH=1Availability or recovery The flaw disrupts use or recovery without a direct safety-control path. Metrics set PH=2 · RE=2 · EC=3 · DP=1 · AT=2 · CH=2Observability or forensic recovery only A logging or forensic gap weakens detection and recovery but is not an exploit primitive. Metrics set PH=0 · RE=0 · EC=0 · DP=1 · AT=0 · CH=0
02 Documented deployment Use the most exposed deployment you can support, not the worst imaginable context. Lab, disabled, or bench use No exposed patient, public, process, or active mission context. Metrics set EXP=0 · CTRL=0Supervised workplace Trained operators, controlled space, and an observable operating process. Metrics set EXP=1 · CTRL=1Hospital or active clinical use Patients or vulnerable users are near the affected function or data path. Metrics set EXP=2 · CTRL=2Home, consumer, or public-adjacent use Untrained users, bystanders, or private environments are exposed. Metrics set EXP=3 · CTRL=2Public embodied operation Autonomous or remote physical systems operate around uncontrolled bystanders. Metrics set EXP=3 · CTRL=3Industrial or critical infrastructure The affected process supports operational safety, continuity, or public services. Metrics set EXP=3 · CTRL=3
03 Path-specific safeguard Credit only a guard that independently bounds this exact harm transition. Independent hardware guard A verified physical, analog, or mechanical guard bounds this harm path. Metrics set GD=0 · CTRL≥1Independent safety controller A safety-rated controller independently validates or stops hazardous commands. Metrics set GD=1 · CTRL≥1Software, procedure, or same-stack guard The safeguard depends on software, procedure, monitoring, or the compromised stack. Metrics set GD=2 · CTRL≥2Unknown, absent, or bypassed guard No path-specific independent guard is documented, or the exploit bypasses it. Metrics set GD=3 · CTRL≥3
04 Scale and recovery Separate repeatability from fleet authority and coordinated recovery burden. One fixed target No evidence that the path scales beyond a single target. Metrics set SR=1 · SX=0 · OR=1 · SYS=0Repeat per device The exploit can repeat, but each device needs separate setup or proximity. Metrics set SR=2 · SX=2 · OR=2 · SYS=1Site or deployment-wide A foothold or local position can affect a site, ward, plant, or deployment group. Metrics set SR=3 · SX=3 · OR=3 · SYS=2Fleet, cloud, or vendor-plane reach A reusable authority or management path can affect many devices or customers. Metrics set SR=4 · SX=4 · OR=4 · SYS=3Synchronized failure or hard recovery Coordinated failure, recall, root rotation, or fleet reprovision is plausible. Metrics set SR=4 · SX=4 · OR=4 · SYS=4