@@ -135,6 +135,15 @@ Execute the calibration as follows:
135135 - 2: Theoretical and highly complex (requires local access, strict
136136 timing).
137137 - 1: Strictly theoretical risk with no known exploit path.
138+ - ** Reachability-in-Practice Modifier:** After determining the base
139+ likelihood, reduce the ` likelihood_score ` by ** 1 or 2** (but not
140+ below 1.0) if the exploit path relies on uncommon or non-default
141+ usage patterns. This applies if:
142+ - The specific tainted parameter is populated from attacker input
143+ only during rare API calls, uncommon configuration fields, or in
144+ data formats rarely processed in the wild.
145+ - The vulnerability requires non-standard or administrative-only
146+ configurations that are rarely enabled in practice.
138147 - ** Context Multiplier (0.1 - 1.0):**
139148 - If ` status ` is ** FALSE_POSITIVE** or ** NEEDS_RESEARCH** , or if
140149 ` production_viability ` is ** NON_VIABLE** : Drop this finding
@@ -171,6 +180,38 @@ Execute the calibration as follows:
171180 ` "PRIVILEGED" `
172181 - ** Evaluate Attacker Position (declared in finding):**
173182 - Read ` attacker_position ` from the finding JSON.
183+ - ** Determine by Barrier, Not Transport:** The
184+ ` attacker_position ` must represent the outermost
185+ boundary that the ** first untrusted principal** (the
186+ ultimate human attacker or external threat actor) must
187+ cross to reach the interface. Do not key on the
188+ transport protocol (e.g., HTTP, gRPC, IPC) or the
189+ immediate protocol peer.
190+ - ** Trace Back to Untrusted Actor:** If the immediate
191+ peer interacting with the interface is a
192+ trusted-by-design component (e.g., an internal
193+ proxy, gateway, message queue, or master
194+ controller), you must trace back the data flow to
195+ find the outermost boundary where the untrusted
196+ actor first enters the system.
197+ - If the interface is bound to ` localhost ` or uses
198+ local IPC (unix sockets, pipes, shared memory), the
199+ position is ` "LOCAL" ` , even if it uses HTTP/TCP
200+ under the hood.
201+ - If the interface is only reachable within a private
202+ network (VPC, corporate network, home LAN, local
203+ network, internal cluster control plane), the
204+ position is ` "INTERNAL_NETWORK" ` (or ` "IN_CLUSTER" `
205+ if restricted to pod-to-pod), even if it is a web
206+ service.
207+ - The position is only ` "EXTERNAL" ` if the interface
208+ is directly reachable from the public internet.
209+ - If the interface requires physical contact, hardware
210+ interaction (e.g., JTAG, debug probes, chip
211+ decapping), or local wireless proximity (e.g., NFC,
212+ Bluetooth), the position must be
213+ ` "PHYSICAL_TEMPORARY" ` or ` "PHYSICAL_LONG_TERM" ` ,
214+ regardless of the protocol used.
174215 - ** Normalize Free-text:** If the value is present but is
175216 a free-text string that does not exactly match one of
176217 the valid enum values (e.g. legacy phrasings), you
@@ -289,17 +330,29 @@ Execute the calibration as follows:
289330
2903313 . ** Critical Sanity Triage (Downgrading & Capping Findings):** Before
291332 determining the final priority, perform a second-level sanity check on the
292- quality of the finding, its context, and accumulated evidence. Check if the
293- ` THREAT_MODEL.md ` defines any ` Calibration Overrides ` (e.g., `LIFT_CAP:
294- PHYSICAL_LONG_TERM`). If an override exists for a finding's position or
295- component, it takes precedence and lifts the corresponding cap. Otherwise,
296- the caps and downgrades below override any upgrades calculated in Section 2
297- (including the Security Control Bypass upgrade), and you ** MUST**
298- force-downgrade or cap the finding's priority and score if it meets any of
299- the following criteria. ** Important: A cap (HIGH or MEDIUM) only limits the
300- maximum allowed score/priority. It must NOT upgrade a lower score/priority
301- (e.g., a finding with a score of 5.0 is naturally MEDIUM and must remain
302- MEDIUM, even if it is subject to a cap at HIGH).**
333+ quality of the finding, its context, and accumulated evidence.
334+
335+ ** Core Principle - Marginal Capability:** The final severity and priority of
336+ a finding are strictly bounded by the * marginal capability* gained by the
337+ attacker over their prerequisite position. If the exploit does not grant the
338+ attacker significant new control, access, or capabilities beyond what is
339+ already inherent to their starting position (or already possessed via
340+ legitimate means), the finding must be capped or downgraded. ** This
341+ principle applies generally to all findings; the specific rules listed below
342+ are common applications of this principle but are not exhaustive.**
343+
344+ Check if the ` THREAT_MODEL.md ` defines any ` Calibration Overrides ` (e.g.,
345+ ` LIFT_CAP: PHYSICAL_LONG_TERM ` ). If an override exists for a finding's
346+ position or component, it takes precedence and lifts the corresponding cap.
347+ Otherwise, the caps and downgrades below (and general applications of the
348+ Marginal Capability principle) override any upgrades calculated in Section 2
349+ (including the Security Control Bypass upgrade). You ** MUST** apply the
350+ specific caps and downgrades below, and should also apply the general
351+ principle to cap or downgrade other findings that offer low marginal
352+ capability. ** Important: A cap (HIGH or MEDIUM) only limits the maximum
353+ allowed score/priority. It must NOT upgrade a lower score/priority (e.g., a
354+ finding with a score of 5.0 is naturally MEDIUM and must remain MEDIUM, even
355+ if it is subject to a cap at HIGH).**
303356
304357 ** Precedence:** Evaluate ALL rules below. If multiple caps apply, the ** most
305358 restrictive** wins (Force-LOW > cap-MEDIUM > cap-HIGH). Record every rule
@@ -335,29 +388,41 @@ Execute the calibration as follows:
335388 - ** Prerequisite Shell Access (Equivalent Primitives):** The attacker
336389 already possesses local shell access on the target container or host
337390 with the ** same or higher** privilege level than the exploit
338- provides, rendering the gained access redundant (e.g., exploiting a
339- bug to get a standard user shell when already logged in as a
340- standard user, or exploiting a local buffer overflow to run commands
341- as root when already running as root). This does NOT apply to
342- low-to-high privilege escalation (e.g., standard user to root),
343- which should cap at MEDIUM.
391+ provides, rendering the gained access redundant under the Principle
392+ of Marginal Capability (e.g., exploiting a bug to get a standard
393+ user shell when already logged in as a standard user, or exploiting
394+ a local buffer overflow to run commands as root when already running
395+ as root). This does NOT apply to low-to-high privilege escalation
396+ (e.g., standard user to root), which should cap at MEDIUM.
344397
345398 - ** Physical Long-Term / Laboratory Access:** If the attack requires
346399 long-term physical access to the device or specialized laboratory
347400 equipment (e.g., fault injection, side-channel analysis, chip
348401 decapping). Force-downgrade to ** LOW (2.0)** due to the extreme
349402 execution barrier and requirement for physical possession.
350403
404+ - ** Trusted-Controller-Mediated Interface (Zero Delta):** If the
405+ vulnerable interface is reachable only from a component that holds
406+ designed-in authoritative control over the target (e.g.,
407+ orchestrator->worker, driver->device firmware, protocol
408+ master->slave, hypervisor->guest, management plane->data plane
409+ node), and the exploit grants ** zero marginal capability** (i.e.,
410+ the controller could already achieve the identical effect or level
411+ of compromise via its standard, legitimate interface),
412+ force-downgrade to ** LOW (2.0)** . (This generalizes the * Standard
413+ Host-to-Guest Attacks* rule below).
414+
351415 - ** Standard Host-to-Guest Attacks:** If the attacker position is
352416 ` HOST_SYSTEM ` (host hypervisor attacking guest) on standard
353417 deployments (non-Confidential Computing). Force-downgrade to ** LOW
354- (2.0)** (equivalent primitives), as the host OS/hypervisor already
355- possesses total control over the guest by design. ** Default
356- assumption:** treat as non-Confidential Computing (this rule fires)
357- UNLESS the Threat Model, code path, or finding description
358- explicitly names Confidential Computing, guest enclaves, TEE, SEV,
359- TDX, SGX, or attestation (in which case apply the CC Host Attacks
360- cap-HIGH rule instead).
418+ (2.0)** as the host OS/hypervisor already possesses total control
419+ over the guest by design, meaning the exploit offers zero marginal
420+ capability over the prerequisite position (equivalent primitives).
421+ ** Default assumption:** treat as non-Confidential Computing (this
422+ rule fires) UNLESS the Threat Model, code path, or finding
423+ description explicitly names Confidential Computing, guest enclaves,
424+ TEE, SEV, TDX, SGX, or attestation (in which case apply the CC Host
425+ Attacks cap-HIGH rule instead).
361426
362427 * ** Force-Cap to HIGH (Cap at 7.9 / Maximum HIGH Priority):**
363428
@@ -413,23 +478,56 @@ Execute the calibration as follows:
413478 against host-level compromise. (If not a CC deployment, see the
414479 Standard Host-to-Guest Attacks rule under LOW).
415480
481+ - ** Trusted-Controller-Mediated Interface (Critical Bypass):** If the
482+ vulnerable interface is reachable only from a designed-in
483+ authoritative controller, and the exploit allows that controller to
484+ bypass target-side ** documented security controls** or
485+ ** safety-of-life limits** it was designed to respect, cap at ** HIGH
486+ (7.9)** . (If the exploit allows lateral reach into a different trust
487+ domain or achieves persistence surviving controller re-provisioning,
488+ do not cap).
489+
416490 * ** Force-Cap to MEDIUM (Cap at 5.9 / Maximum MEDIUM Priority):**
417491
418492 - ** Local Attack Vector:** Vulnerabilities requiring local shell
419493 access (e.g., local privilege escalation, SUID exploitation) without
420494 VM escape. (Downgrade to LOW/2.0 if it only affects a single user's
421495 isolated data).
422- - ** Intra-Customer / Same-Tenant:** Attacks restricted to the same
423- tenant boundary the attacker already controls, with no cross-tenant
424- escalation or host compromise.
496+ - ** Self-Contained Blast Radius:** If the maximum impact of the
497+ exploit is confined to resources, data, or execution contexts that
498+ the triggering principal already owns or has full designed-in
499+ authority over — their own account, tenant, project, namespace,
500+ container, VM, device, or single-user installation — and does not
501+ cross any isolation boundary between mutually-distrusting
502+ principals, cap at ** MEDIUM (5.9)** .
503+ - The exploit may grant genuinely new capability within that
504+ domain (e.g., API-user -> shell in their own container), but the
505+ deployment's core isolation guarantees to other parties still
506+ hold. This is a blast-radius bound, distinct from the Marginal
507+ Capability principle (which bounds by new capability; this
508+ bounds by who is affected).
509+ - Do ** NOT** apply this cap if the exploit:
510+ - reaches another principal's resources (cross-tenant,
511+ cross-user, cross-account),
512+ - touches shared or multi-party infrastructure (shared cache,
513+ shared filesystem, operator control plane, co-tenant
514+ side-channel),
515+ - places the attacker's domain upstream of others (build node,
516+ CI runner, package registry, model-serving host — i.e., a
517+ supply-chain position), or
518+ - persists in a way that survives the principal's own resource
519+ lifecycle and could later affect a different principal
520+ reusing that slot.
425521 - ** Rarely Exposed Components:** Findings in components documented as
426522 'rarely exposed' or 'unlikely to be user controlled'.
427523 - ** Equivalent Primitives (No Boundary Breach):** The attacker profile
428524 capable of triggering the vulnerability already possesses equivalent
429525 access, privileges, or capabilities (primitives) through standard
430526 system features (e.g., an admin exploiting a bug to download a file
431- they can already download via the UI). Cap at ** MEDIUM (5.9)** to
432- maintain visibility for defense-in-depth cleanup.
527+ they can already download via the UI). Because this offers low
528+ marginal capability over their prerequisite position, cap at
529+ ** MEDIUM (5.9)** to maintain visibility for defense-in-depth
530+ cleanup.
433531 - ** Documented Insecure Configurations:** Non-default configurations
434532 that are explicitly documented in public manuals as insecure,
435533 diagnostic-only, or strictly non-production. Cap at ** MEDIUM
@@ -446,6 +544,13 @@ Execute the calibration as follows:
446544 (5.9)** , unless the exploit results in escaping the container
447545 boundary (to host node) or cross-tenant escalation.
448546
547+ - ** Trusted-Controller-Mediated Interface (Standard Bypass):** If the
548+ vulnerable interface is reachable only from a designed-in
549+ authoritative controller, and the exploit allows that controller to
550+ bypass target-side ** standard safety or sanity limits** (but not
551+ critical safety-of-life or documented security controls) it was
552+ expected to respect, cap at ** MEDIUM (5.9)** .
553+
4495544 . ** Determine Priority:**
450555
451556 - ** CRITICAL (8.0 - 10.0):** Immediate action required. Very high hazard
0 commit comments