This is the exact demo — every step is a single read-only path-lookup on your live snapshot. No agent, no scan, no change. Watch reachability re-rank the risk in front of you.
The device everyone was patching is contained. The device nobody was watching owns your data centre. Same question, two answers. CVSS would never surface that — your network just did.
Every step is a path-lookup — a read over your existing snapshot. Nothing is scanned, launched, or changed. The same segregation-of-duties boundary you're built on.
Each verdict is IP Fabric's own forwarding calculation off your route + ACL tables — a block dies at a named control; an open path has none. The asymmetry is the signal.
We show a network-layer path to the target — not that a service answered, and never "exploitable." We surface the precondition and the blast radius; the exploit question is exactly what this forces you to ask.
On a lab the numbers are illustrative; on your production snapshot it finds the device whose reachability contradicts its risk ranking — wherever that is.