{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "ec280dee40e179159a9bebea5af1a2b969146ac12cd7a8b34f0770b570bc87b6",
    "authored_runtime_manifest_sha256": "b958a1caa4545b9d645d3cf91f98e9e28aa0bf85f44282e12e0842405a1c8bb9",
    "authored_verdict_sha256": "9d28a53034a51172f8e7c236dfa75812f98bbd504167a6542d6cbf81ad315f30",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "b34e3344-d221-4aec-87ee-721693f518ff",
    "c001d3b0-2f40-4cce-ba39-5be3a3b9d5cc",
    "31591647-1e2a-4ed8-a2ae-041dcc61cc7c"
  ],
  "attacker_controlled_input": "Rejected SSH password authentication attempt for username -2, client-requested rekey, session/PTY/exec requests, and NUL-delimited fd-2 policy fields",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "code_execution",
  "claimed_surface": "network_protocol",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "code_execution",
  "read_write_primitive_observed": true,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "TCP SSH transport -> rejected -2 userauth -> client rekey -> session channel -> PTY exec -> /nova/bin/login fd-2 trusted-field parser -> RouterOS /file add",
  "validated_surface": "network_protocol"
}
