AI Bridge / Watcher Artifact

CVSS Environmental Dashboard

Interactive cloud-ready view of the PCI segmented lab run. The dashboard connects local environmental evidence, CVSS Environmental labels, before-after score deltas, and audit-trace material used by the manuscript.

Latest run
pci_segmented_lab_20260517_143146
Case
pci_segmented_lab
6
Findings
12
Assessments
2
Downgraded
4
Unchanged
-0.267
Mean delta

Before/after environmental effects

FindingAssetCVETypeBeforeAfterDeltaMAVEffect
F-001A-CORP-SRVCVE-2016-0036SYS8.88.0-0.8N to Adowngraded
F-002POS-01CVE-2016-0469SYS7.87.80.0L to Lunchanged
F-003ADMIN-01CVE-2016-3234APP8.88.0-0.8N to Adowngraded
F-004WIRELESS-LEGACY-01CVE-2016-1619APP7.87.80.0N to Nunchanged
F-005CORE-SW-01CVE-2016-6441SYS9.79.70.0A to Aunchanged
F-006CORE-SW-01CVE-2016-6428SYS8.88.80.0A to Aunchanged

Assessment rows

FindingStateAssetBaseEnvCRIRARMAVExpected
F-001beforeA-CORP-SRV8.88.8MMHN
F-001afterA-CORP-SRV8.88.0MMHA
F-002beforePOS-017.87.8HHHL
F-002afterPOS-017.87.8HHHL
F-003beforeADMIN-018.88.8MMMN
F-003afterADMIN-018.88.0MMMA
F-004beforeWIRELESS-LEGACY-018.87.8LLMN
F-004afterWIRELESS-LEGACY-018.87.8LLMN
F-005beforeCORE-SW-019.69.7MHHA
F-005afterCORE-SW-019.69.7MHHA
F-006beforeCORE-SW-018.38.8MHHA
F-006afterCORE-SW-018.38.8MHHA

Run manifest

Input hashes make the run reproducible and auditable.

8
case files hashed

Audit trace sample

[
  {
    "cve": "CVE-2016-0036",
    "state": "before",
    "metric": "CR/IR/AR",
    "reason": "asset=A-CORP-SRV scope_before=in_scope role=corporate_service",
    "source": "business_impact.yaml + pci_scope.yaml + assets.csv",
    "asset_id": "A-CORP-SRV",
    "finding_id": "F-001"
  },
  {
    "cve": "CVE-2016-0036",
    "state": "before",
    "metric": "ModifiedBaseDefaults",
    "reason": "Unchanged modified metrics inherit base values unless local evidence overrides them.",
    "source": "vulnerabilities.csv",
    "asset_id": "A-CORP-SRV",
    "finding_id": "F-001"
  },
  {
    "cve": "CVE-2016-0036",
    "state": "after",
    "metric": "CR/IR/AR",
    "reason": "asset=A-CORP-SRV scope_after=out_of_scope role=corporate_service",
    "source": "business_impact.yaml + pci_scope.yaml + assets.csv",
    "asset_id": "A-CORP-SRV",
    "finding_id": "F-001"
  },
  {
    "cve": "CVE-2016-0036",
    "state": "after",
    "metric": "MAV",
    "reason": "base AV=N but external_exposure_after=internal_only; network attack constrained to adjacent/internal segment.",
    "source": "assets.csv + firewall_rules.yaml",
    "asset_id": "A-CORP-SRV",
    "finding_id": "F-001"
  },
  {
    "cve": "CVE-2016-0036",
    "state": "after",
    "metric": "ModifiedBaseDefaults",
    "reason": "Unchanged modified metrics inherit base values unless local evidence overrides them.",
    "source": "vulnerabilities.csv",
    "asset_id": "A-CORP-SRV",
    "finding_id": "F-001"
  },
  {
    "cve": "CVE-2016-0469",
    "state": "before",
    "metric": "CR/IR/AR",
    "reason": "asset=POS-01 scope_before=in_scope role=payment_processing",
    "source": "business_impact.yaml + pci_scope.yaml + assets.csv",
    "asset_id": "POS-01",
    "finding_id": "F-002"
  },
  {
    "cve": "CVE-2016-0469",
    "state": "before",
    "metric": "ModifiedBaseDefaults",
    "reason": "Unchanged modified metrics inherit base values unless local evidence overrides them.",
    "source": "vulnerabilities.csv",
    "asset_id": "POS-01",
    "finding_id": "F-002"
  },
  {
    "cve": "CVE-2016-0469",
    "state": "after",
    "metric": "CR/IR/AR",
    "reason": "asset=POS-01 scope_after=in_scope role=payment_processing",
    "source": "business_impact.yaml + pci_scope.yaml + assets.csv",
    "asset_id": "POS-01",
    "finding_id": "F-002"
  },
  {
    "cve": "CVE-2016-0469",
    "state": "after",
    "metric": "ModifiedBaseDefaults",
    "reason": "Unchanged modified metrics inherit base values unless local evidence overrides them.",
    "source": "vulnerabilities.csv",
    "asset_id": "POS-01",
    "finding_id": "F-002"
  },
  {
    "cve": "CVE-2016-3234",
    "state": "before",
    "metric": "CR/IR/AR",
    "reason": "asset=ADMIN-01 scope_before=in_scope role=administration",
    "source": "business_impact.yaml + pci_scope.yaml + assets.csv",
    "asset_id": "ADMIN-01",
    "finding_id": "F-003"
  },
  {
    "cve": "CVE-2016-3234",
    "state": "before",
    "metric": "ModifiedBaseDefaults",
    "reason": "Unchanged modified metrics inherit base values unless local evidence overrides them.",
    "source": "vulnerabilities.csv",
    "asset_id": "ADMIN-01",
    "finding_id": "F-003"
  },
  {
    "cve": "CVE-2016-3234",
    "state": "after",
    "metric": "CR/IR/AR",
    "reason": "asset=ADMIN-01 scope_after=out_of_scope role=administration",
    "source": "business_impact.yaml + pci_scope.yaml + assets.csv",
    "asset_id": "ADMIN-01",
    "finding_id": "F-003"
  }
]