01 / Attack path
How the boundary is crossed
A firewall tool returns HTTP 200 for a rule update, but the edge devices never receive the policy.
- 01Lower-trust input
- 02Attempted instruction
- 03Protected action
- 04Enforced decision
02 / Containment
Where bounded authority limits the effect
Bind decision and executor receipt to an independent read of the authoritative firewall state after propagation.
03 / Failure and evidence
The attacker’s opportunity and the defender’s record
An agent reports protection complete while the old rule remains active.
Record tool response, observation source and time, mismatch and remediation status.
04 / Canonical scope
Why this reference stands alone
False-success evidence concerns a misleading record; this page owns missing outcome verification.
Protocol or attack trace
False-completion check
Firewall tool returns HTTP 200; effective edge rule remains old after propagation window.
Mark result partial or unknown until authoritative edge read shows new rule.
Primary references