vExpertAI × IP Fabric · Executable Exposure

One real finding, carried through all three engines.

The forgotten device your scanner never flagged — reached across the real topology, matched to vendor-confirmed CVEs, and described end-to-end. All read-only.

Generated from a real run — not hand-wired

This page is rendered from an actual read-only sweep on 2026-08-01T14:32:31+00:00 against IP Fabric snapshot 0a7018be. Nothing was scanned or executed. The three engines are still separate — this is the integrated pipeline's output, produced by one command.

SeeIP Fabric — reachability from real config
HWLAB-FW-C5510 cisco asa 9.1(7)16
10.66.123.110 · 6 hops · HWLAB-HPA5500-SW2 → HWLAB-HPA5500-SW1 → HWLAB-HPE1920
  • no ACL, zone-firewall, NAT or PBR policy evaluated this flow
KnowVendor-truth CVEs for this exact build
CVE-2020-3259 CVE-2018-0296 CVE-2020-3125 CVE-2020-3187 CVE-2020-3191 CVE-2020-3196 CVE-2020-3254 CVE-2019-12673

+14 more vendor-confirmed CVE(s) [10.66.123.110] — capped for display

ForeseeDescribe-only attack path — never executed
HWLAB-FW-C5510 (cisco asa 9.1(7)16) has an uncontrolled network path to 10.66.123.110 — 6 hops, with no ACL, zone-firewall, NAT or PBR policy evaluating the flow. Known status: end-of-support software train; CISA-KEV issues affecting the ASA 9.x SSL-VPN/web stack; CVE-2020-3259 — CISA-KEV, vendor-confirmed for this build; CVE-2018-0296 — CISA-KEV, vendor-confirmed for this build. Vendor-confirmed advisories in scope: CVE-2020-3259, CVE-2018-0296, CVE-2020-3125, CVE-2020-3187, CVE-2020-3191, CVE-2020-3196. Precondition: an attacker with a foothold on any segment that reaches this device. Blast radius: 10.66.123.110. This describes a network-layer path and the device's known status — not a confirmed live service, and not a claim of exploitability.
▲ describe-only red layer · gates passed · no tools · no ungrounded CVE · reachable paths only

The rest of the sweep — re-ranked by reachability

L71FW13-HA2/rootno-routeno route to destination — nothing is enforcing this
L71FW7/rootdefault-denyblocked by zoneFw main rule [0,2] at device:2938 loopback-mgmt (the policy's default rule)
L71FW13-HA1/mrjohnsondefault-denyblocked by acl TSF4 rule [0,0,9] at L66ACC23 Et0/1 (the policy's default rule)